Bowei Tian

dblp:368/9393 · DBLP profile ↗
← Back
6ranked-venue papers
2as first author
6since 2021 · last 2026
0009-0005-7275-7955ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 4 · 2 first-author · 4 since 2021Security and privacy · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Artificial intelligence
4 papers
Trustworthy machine learning · 47% Efficient and distributed learning · 22% Deep learning architectures and training · 21%
Computer architecture, parallel and distributed computing, and storage systems
1 paper
Electronic design automation · 94% Performance modeling and evaluation · 6%
Network and information security
2 papers
Security and privacy of machine learning · 100%

Topics — the 17 heaviest of 18, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Security and privacy of machine learning › adversarial attack
backdoor attack
1.922026
Megatron: Evasive Clean-Label Backdoor Attacks Against Vision Transformer · IEEE Trans. Dependable Secur. Comput. 2026
An Effective and Resilient Backdoor Attack Framework Against Deep Neural Networks and Vision Transformers · IEEE Trans. Dependable Secur. Comput. 2025
Machine learning › Trustworthy machine learning
fairness
1.622025
Towards counterfactual fairness through auxiliary variables · ICLR 2025
FairViT: Fair Vision Transformer via Adaptive Masking · ECCV (65) 2024
Security and privacy of machine learning › poisoning attack
clean-label attack
1.012026
Megatron: Evasive Clean-Label Backdoor Attacks Against Vision Transformer · IEEE Trans. Dependable Secur. Comput. 2026
Machine learning › Trustworthy machine learning › fairness
causal fairness
0.912025
Towards counterfactual fairness through auxiliary variables · ICLR 2025
Machine learning › Trustworthy machine learning › fairness › causal fairness
counterfactual fairness
0.912025
Towards counterfactual fairness through auxiliary variables · ICLR 2025
Machine learning › Efficient and distributed learning › adaptive computation
dynamic layer skipping
0.912025
Router-Tuning: A Simple and Effective Approach for Dynamic Depth · EMNLP 2025
Machine learning › Deep learning architectures and training
mixture of experts
0.912025
Router-Tuning: A Simple and Effective Approach for Dynamic Depth · EMNLP 2025
Machine learning › Efficient and distributed learning
model compression
0.912025
Router-Tuning: A Simple and Effective Approach for Dynamic Depth · EMNLP 2025
Electronic design automation › hardware verification and test › formal verification
equivalence checking
0.912025
SymRTLO: Enhancing RTL Code Optimization with LLMs and Neuron-Inspired Symbolic Reasoning · NeurIPS 2025
Electronic design automation
hardware verification and test
0.912025
SymRTLO: Enhancing RTL Code Optimization with LLMs and Neuron-Inspired Symbolic Reasoning · NeurIPS 2025
Electronic design automation
logic synthesis
0.912025
SymRTLO: Enhancing RTL Code Optimization with LLMs and Neuron-Inspired Symbolic Reasoning · NeurIPS 2025
Electronic design automation › logic synthesis › digital system synthesis
RTL optimization
0.912025
SymRTLO: Enhancing RTL Code Optimization with LLMs and Neuron-Inspired Symbolic Reasoning · NeurIPS 2025
Machine learning › Representation and self-supervised learning › representation learning › unsupervised representation learning › self-supervised representation learning › masked modeling
adaptive masking
0.812024
FairViT: Fair Vision Transformer via Adaptive Masking · ECCV (65) 2024
Machine learning › Deep learning architectures and training › transformer
vision transformer
0.812024
FairViT: Fair Vision Transformer via Adaptive Masking · ECCV (65) 2024
Machine learning › Trustworthy machine learning
robustness
0.312025
An Effective and Resilient Backdoor Attack Framework Against Deep Neural Networks and Vision Transformers · IEEE Trans. Dependable Secur. Comput. 2025
Electronic design automation › logic synthesis
finite state machine optimization
0.312025
SymRTLO: Enhancing RTL Code Optimization with LLMs and Neuron-Inspired Symbolic Reasoning · NeurIPS 2025
Performance modeling and evaluation › state space exploration
state aggregation
0.312025
SymRTLO: Enhancing RTL Code Optimization with LLMs and Neuron-Inspired Symbolic Reasoning · NeurIPS 2025

Methods — techniques the papers use, named apart from their topics

quality-of-experience loss · 1.7co-optimized attack · 1.7alternating retraining · 1.7surrogate model · 1.0latent loss · 1.0attention diffusion loss · 1.0symbolic reasoning · 0.9router fine-tuning · 0.9retrieval-augmented generation · 0.9moe layer skipping · 0.9large language model · 0.9formal equivalence checking · 0.9exogenous variable · 0.9causal reasoning · 0.9auxiliary variables · 0.9attention layer skipping · 0.9abstract syntax tree · 0.9adaptive masking · 0.8
YearPublicationVenuePosition
2026 Megatron: Evasive Clean-Label Backdoor Attacks Against Vision Transformer
abstract
Vision transformers have achieved impressive performance in various vision-related tasks, but their vulnerability to backdoor attacks is under-explored. A handful of existing works focus on dirty-label attacks with wrongly-labeled poisoned training samples, which may fail if a benign model trainer corrects the labels. In this paper, we proposeMegatron, an evasive clean-label backdoor attack against vision transformers, where the attacker injects the backdoor without manipulating the data-labeling process. To generate an effective trigger, we employ a local surrogate vision transformer to approximate the victim model and customize two attention-based loss terms: latent loss and attention diffusion loss. The latent loss aligns the last attention layer between triggered samples and clean samples of the target label. The attention diffusion loss emphasizes the attention diffusion area that encompasses the trigger. A theoretical analysis is provided to underpin the rationale behind the attention diffusion loss. Extensive experiments on CIFAR-10, GTSRB, CIFAR-100, and Tiny ImageNet demonstrate the effectiveness ofMegatron.Megatroncan achieve attack success rates of over 90% even when the position of the trigger is slightly shifted during testing. Furthermore,Megatronachieves better evasiveness than baselines regarding both human visual inspection and defense strategies (i.e., DBAVT, BAVT, Beatrix, TeCo, and SAGE).
Xueluan Gong, Bowei Tian, Meng Xue 0001, Shuaike Li, Yanjiao Chen, Qian Wang 0002
IEEE Trans. Dependable Secur. Comput.2
2025 Router-Tuning: A Simple and Effective Approach for Dynamic Depth
abstract
The Mixture of Depths (MoD) was introduced to improve computational efficiency by dynamically skipping less important layers, reducing redundant computation while maintaining model capacity.Despite its promise, existing MoD approaches remain under-explored and face two main challenges: (1) high training costs due to the need to train the entire model along with the routers that determine which layers to skip, and (2) performance degradation when important layers are bypassed.In response to the first issue, we propose Router-Tuning, which fine-tunes only the routers on a small dataset, drastically reducing the computational overhead associated with full model training.For the second challenge, we investigate Router-Tuning across different architectures and granularities, demonstrating its effectiveness on Attention layers and MoE layers.This method preserves the model's performance while significantly enhancing computational and memory efficiency.Extensive experiments demonstrate that our approach delivers competitive results while dramatically improving the computation efficiency, e.g., 21% speedup and only a 0.2% performance drop.
Shwai He, Tao Ge 0001, Guoheng Sun, Bowei Tian, Xiaoyang Wang 0001, Dong Yu 0001
EMNLP4
2025 Towards counterfactual fairness through auxiliary variables
abstract
The challenge of balancing fairness and predictive accuracy in machine learning models, especially when sensitive attributes such as race, gender, or age are considered, has motivated substantial research in recent years. Counterfactual fairness ensures that predictions remain consistent across counterfactual variations of sensitive attributes, which is a crucial concept in addressing societal biases. However, existing counterfactual fairness approaches usually overlook intrinsic information about sensitive features, limiting their ability to achieve fairness while simultaneously maintaining performance. To tackle this challenge, we introduce EXOgenous Causal reasoning (EXOC), a novel causal reasoning framework motivated by exogenous variables. It leverages auxiliary variables to uncover intrinsic properties that give rise to sensitive attributes. Our framework explicitly defines an auxiliary node and a control node that contribute to counterfactual fairness and control the information flow within the model. Our evaluation, conducted on synthetic and real-world datasets, validates EXOC's superiority, showing that it outperforms state-of-the-art approaches in achieving counterfactual fairness without sacrificing accuracy. Our code is available at https://github.com/CASE-Lab-UMD/counterfactual_fairness_2025.
Bowei Tian, Shwai He, Wanghao Ye, Guoheng Sun, Yucong Dai, Yongkai Wu, Ang Li 0005
ICLR1
2025 SymRTLO: Enhancing RTL Code Optimization with LLMs and Neuron-Inspired Symbolic Reasoning
abstract
Optimizing Register Transfer Level (RTL) code is crucial for improving the efficiency and performance of digital circuits in the early stages of synthesis. Manual rewriting, guided by synthesis feedback, can yield high-quality results but is time-consuming and error-prone. Most existing compiler-based approaches have difficulty handling complex design constraints. Large Language Model (LLM)-based methods have emerged as a promising alternative to address these challenges. However, LLM-based approaches often face difficulties in ensuring alignment between the generated code and the provided prompts. This paper introduces SymRTLO, a neuron-symbolic framework that integrates LLMs with symbolic reasoning for the efficient and effective optimization of RTL code. Our method incorporates a retrieval-augmented system of optimization rules and Abstract Syntax Tree (AST)-based templates, enabling LLM-based rewriting that maintains syntactic correctness while minimizing undesired circuit behaviors. A symbolic module is proposed for analyzing and optimizing finite state machine (FSM) logic, allowing fine-grained state merging and partial specification handling beyond the scope of pattern-based compilers. Furthermore, a fast verification pipeline, combining formal equivalence checks with test-driven validation, further reduces the complexity of verification. Experiments on the RTL-Rewriter benchmark with Synopsys Design Compiler and Yosys show that SymRTLO improves power, performance, and area (PPA) by up to 43.9%, 62.5%, and 51.1%, respectively, compared to the state-of-the-art methods. We will release the code as open source upon the paper's acceptance.
Wanghao Ye, Ping Guo 0007, Yexiao He, Bowei Tian, Shwai He, Guoheng Sun, Zheyu Shen, Ankur Srivastava 0001, Qingfu Zhang 0001, Gang Qu 0001, Ang Li 0005
NeurIPS6
2025 An Effective and Resilient Backdoor Attack Framework Against Deep Neural Networks and Vision Transformers
abstract
Recent studies have revealed the vulnerability of Deep Neural Network (DNN) models to backdoor attacks. However, existing backdoor attacks arbitrarily set the trigger mask or use a randomly selected trigger, which restricts the effectiveness and robustness of the generated backdoor triggers. In this paper, we propose a novel attention-based mask generation methodology that searches for the optimal trigger shape and location. We also introduce a Quality-of-Experience (QoE) term into the loss function and carefully adjust the transparency value of the trigger in order to make the backdoored samples to be more natural. To further improve the prediction accuracy of the victim model, we propose an alternating retraining algorithm in the backdoor injection process. The victim model is retrained with mixed poisoned datasets in even iterations and with only benign samples in odd iterations. Besides, we launch the backdoor attack under a co-optimized attack framework that alternately optimizes the backdoor trigger and backdoored model to further improve the attack performance. Apart from DNN models, we also extend our proposed attack method against vision transformers. We evaluate our proposed method with extensive experiments on VGG-Flower, CIFAR-10, GTSRB, CIFAR-100, and ImageNette datasets. It is shown that we can increase the attack success rate by as much as 82% over baselines when the poison ratio is low and achieve a high QoE of the backdoored samples. Our proposed backdoor attack framework also showcases robustness against state-of-the-art backdoor defenses.
Xueluan Gong, Bowei Tian, Meng Xue 0001, Yuan Wu 0007, Yanjiao Chen, Qian Wang 0002
IEEE Trans. Dependable Secur. Comput.2
2024 FairViT: Fair Vision Transformer via Adaptive Masking
Bowei Tian, Ruijie Du, Yanning Shen
ECCV (65)1