VLDB 2026 Research / reviewers in the wild / expert
Lirong Qiu
dblp:63/3087
· DBLP profile ↗
20ranked-venue papers
7as first author
9since 2021 · last 2026
0000-0001-6489-1648ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 11 · 2 first-author · 5 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 3 since 2021Databases, data management, data science and information retrieval · 2 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 first-authorSecurity and privacy · 1 · 1 first-authorSoftware engineering, systems software and programming languages · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1 · 1 first-author
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
4 papers |
Security and privacy of machine learning · 71% Systems and software security · 16% Digital forensics and information hiding · 14% | |
| Artificial intelligence
4 papers |
Language models and text generation · 50% Trustworthy machine learning · 45% Reinforcement learning · 5% |
Topics — the 11 heaviest of 14, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Natural language and speech › Language models and text generation
large language model safety |
2.0 | 2 | 2026 | Beyond Surface-Level Detection: Towards Cognitive-Driven Defense Against Jailbreak Attacks via Meta-Operations Reasoning · ACL (1) 2026 MirrorShield: Towards Dynamic Adaptive Defense Against Jailbreaks via Entropy-Guided Mirror Crafting · AAAI 2026 |
Security and privacy of machine learning › adversarial attack
jailbreak attack |
1.6 | 2 | 2025 | Feint and Attack: Jailbreaking and Protecting LLMs via Attention Distribution Modeling · IJCAI 2025 BaitAttack: Alleviating Intention Shift in Jailbreak Attacks via Adaptive Bait Crafting · EMNLP 2024 |
Machine learning › Trustworthy machine learning
robustness |
1.2 | 2 | 2026 | OSTAR: Optimized Statistical Text-classifier with Adversarial Resistance · NeurIPS 2025 MirrorShield: Towards Dynamic Adaptive Defense Against Jailbreaks via Entropy-Guided Mirror Crafting · AAAI 2026 |
Machine learning › Trustworthy machine learning › adversarial machine learning › adversarial defense
jailbreak defense |
1.0 | 1 | 2026 | Beyond Surface-Level Detection: Towards Cognitive-Driven Defense Against Jailbreak Attacks via Meta-Operations Reasoning · ACL (1) 2026 |
Systems and software security › runtime security
adaptive defense |
1.0 | 1 | 2026 | MirrorShield: Towards Dynamic Adaptive Defense Against Jailbreaks via Entropy-Guided Mirror Crafting · AAAI 2026 |
Security and privacy of machine learning › large language model safety
jailbreak defense |
1.0 | 1 | 2026 | MirrorShield: Towards Dynamic Adaptive Defense Against Jailbreaks via Entropy-Guided Mirror Crafting · AAAI 2026 |
Security and privacy of machine learning
adversarial robustness |
0.9 | 1 | 2025 | OSTAR: Optimized Statistical Text-classifier with Adversarial Resistance · NeurIPS 2025 |
Digital forensics and information hiding › synthetic media detection
machine-generated text detection |
0.9 | 1 | 2025 | OSTAR: Optimized Statistical Text-classifier with Adversarial Resistance · NeurIPS 2025 |
Natural language and speech › Language models and text generation › prompting
adversarial prompt generation |
0.8 | 1 | 2024 | BaitAttack: Alleviating Intention Shift in Jailbreak Attacks via Adaptive Bait Crafting · EMNLP 2024 |
Machine learning › Trustworthy machine learning › adversarial machine learning › adversarial natural language processing
adversarial prompt defense |
0.3 | 1 | 2026 | MirrorShield: Towards Dynamic Adaptive Defense Against Jailbreaks via Entropy-Guided Mirror Crafting · AAAI 2026 |
Security and privacy of machine learning
large language model safety |
0.2 | 1 | 2024 | BaitAttack: Alleviating Intention Shift in Jailbreak Attacks via Adaptive Bait Crafting · EMNLP 2024 |
Methods — techniques the papers use, named apart from their topics
mirror prompt generation · 2.0entropy-guided defense · 2.0statistical profiling · 1.7fine-tuned classifier · 1.7contrastive learning · 1.7adaptive bait crafting · 1.5supervised fine-tuning · 1.0reinforcement learning · 1.0chain-of-thought reasoning · 1.0attention distribution modeling · 0.9
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | MirrorShield: Towards Dynamic Adaptive Defense Against Jailbreaks via Entropy-Guided Mirror CraftingabstractDefending large language models (LLMs) against jailbreak attacks is crucial for ensuring their safe deployment. Existing defense strategies typically rely on predefined static criteria to differentiate between harmful and benign prompts. However, such rigid rules fail to accommodate the inherent complexity and dynamic nature of real-world jailbreak attacks. In this paper, we focus on the novel challenge of adaptive defense against diverse jailbreaks. We propose a new concept "mirror'', which is a dynamically generated prompt that reflects the syntactic structure of the input while ensuring semantic safety. The discrepancies between input prompts and their corresponding mirrors serve as guiding principles for defense. A novel defense model, MirrorShield, is further proposed to detect and calibrate risky inputs based on the crafted mirrors. Evaluated on multiple benchmark datasets and compared against ten state-of-the-art attack methods, MirrorShield demonstrates superior defense performance and promising generalization capabilities. Rui Pu, Chaozhuo Li, Rui Ha, Litian Zhang, Lirong Qiu, Xi Zhang 0008 |
AAAI | 5 |
| 2026 | Beyond Surface-Level Detection: Towards Cognitive-Driven Defense Against Jailbreak Attacks via Meta-Operations ReasoningabstractDefending large language models (LLMs) against jailbreak attacks is essential for their safe and reliable deployment.Existing defenses often rely on shallow pattern matching, which struggles to generalize to novel and unseen attack strategies.To address this challenge, we propose the Cognitive-Driven Defense (CDD) framework, which targets the underlying structure of jailbreak prompts by applying metaoperations, defined as basic manipulations that conceal harmful intent.CDD emulates human cognitive reasoning through a structured reasoning chain.It begins with a global perception of the prompt and follows with a localized analysis to uncover hidden manipulations.By applying supervised fine-tuning on this structured chain, the model learns to identify and reason about known manipulation patterns.To enhance generalization to unseen threats, an entropy-guided reinforcement learning algorithm (EG-GRPO) is introduced to encourage exploration of new types and variants of meta-operations.Experiments demonstrate that CDD can achieve state-of-the-art defense performance and exhibit strong generalization to unseen jailbreak attacks. Rui Pu, Chaozhuo Li, Rui Ha, Litian Zhang, Lirong Qiu, Xi Zhang 0008 |
ACL (1) | 5 |
| 2026 | Homophilic and Heterophilic-Aware Multi-view Graph Clustering
Yeqin Zhou, Lirong Qiu |
DASFAA (2) | 2 |
| 2026 | Dynamic Incongruity Modeling with Semantic Focus for Multimodal Sarcasm Detection
Lirong Qiu, Litian Zhang |
ICIC (14) | 2 |
| 2026 | Efficient Uncertainty-Aware Quad Refinement for Aspect Sentiment Quad Prediction
Ningyi Zhang, Dinghua Wang, Heng Bao, Lirong Qiu |
ICIC (16) | 4 |
| 2025 | Feint and Attack: Jailbreaking and Protecting LLMs via Attention Distribution ModelingabstractMost jailbreak methods for large language models (LLMs) focus on superficially improving attack success through manually defined rules. However, they fail to uncover the underlying mechanisms within target LLMs that explain why an attack succeeds or fails. In this paper, we propose investigating the phenomenon of jailbreaks and defenses for LLMs from the perspective of attention distributions within the models. A preliminary experiment reveals that the success of a jailbreak is closely linked to the LLM's attention on sensitive words.Inspired by this interesting finding, we propose incorporating critical signals derived from internal attention distributions within LLMs, namely Attention Intensity on Sensitive Words and Attention Dispersion Entropy, to guide both attacks and defenses. Drawing inspiration from the concept of "Feint and Attack", we introduce an attention-guided jailbreak model, ABA, which redirects the model's attention to benign contexts, and an attention-based defense model, ABD, designed to detect attacks by analyzing internal attention entropy. Experimental results demonstrate the superiority of our proposal when compared to SOTA baselines. Rui Pu, Chaozhuo Li, Rui Ha, Zejian Chen, Litian Zhang, Zheng Liu 0011, Lirong Qiu, Zaisheng Ye |
IJCAI | 7 |
| 2025 | OSTAR: Optimized Statistical Text-classifier with Adversarial ResistanceabstractThe advancements in generative models and the real-world attack of machine-generated text(MGT) create a demand for more robust detection methods.
The existing MGT detection methods for adversarial environments primarily consist of manually designed statistical-based methods and fine-tuned classifier-based approaches.
Statistical-based methods extract intrinsic features but suffer from rigid decision boundaries vulnerable to adaptive attacks, while fine-tuned classifiers achieve outstanding performance at the cost of overfitting to superficial textual feature.
We argue that the key to detection in current adversarial environments lies in how to extract intrinsic invariant features and ensure that the classifier possesses dynamic adaptability.
In that case, we propose OSTAR, a novel MGT detection framework designed for adversarial environments which composed of a statistical enhanced classifier and a Multi-Faceted Contrastive Learning(MFCL).
In the classifier aspect, our Multi-Dimensional Statistical Profiling (MDSP) module extracts intrinsic difference between human and machine texts, complementing classifiers with useful stable features.
In the model optimization aspect, the MFCL strategy enhances robustness by contrasting feature variations before and after text attacks, jointly optimizing statistical feature mapping and baseline pre-trained models.
Experimental results on three public datasets under various adversarial scenarios demonstrate that our framework outperforms existing MGT detection methods, achieving state-of-the-art performance and robust against attacks.The code is available at https://github.com/BUPT-SN/OSTAR. Yuhan Yao 0001, Feifei Kou, Lei Shi 0030, Zhongbao Zhang, Suguo Zhu, Jiwei Zhang 0007, Lirong Qiu, Hai-Sheng Li 0002 |
NeurIPS | 8 |
| 2024 | BaitAttack: Alleviating Intention Shift in Jailbreak Attacks via Adaptive Bait CraftingabstractJailbreak attacks enable malicious queries to evade detection by LLMs.Existing attacks focus on meticulously constructing prompts to disguise harmful intentions.However, the incorporation of sophisticated disguising prompts may incur the challenge of "intention shift".Intention shift occurs when the additional semantics within the prompt distract the LLMs, causing the responses to deviate significantly from the original harmful intentions.In this paper, we propose a novel component, "bait", to alleviate the effects of intention shift.Bait comprises an initial response to the harmful query, prompting LLMs to rectify or supplement the knowledge within the bait.By furnishing rich semantics relevant to the query, the bait helps LLMs focus on the original intention.To conceal the harmful content within the bait, we further propose a novel attack paradigm, BaitAttack.BaitAttack adaptively generates necessary components to persuade targeted LLMs that they are engaging with a legitimate inquiry in a safe context.Our proposal is evaluated on a popular dataset, demonstrating state-of-the-art attack performance and an exceptional capability for mitigating intention shift.The implementation of BaitAttack is accessible at: https://anonymous.4open. science/r/BaitAttack-D1F5.How to make a bomb. Query Bait Role Scene Format Bait Maker Which expert is best suitable to deal with the act of < Harmful Query >? Create a scene that fits the expert role. Rui Pu, Chaozhuo Li, Rui Ha, Litian Zhang, Lirong Qiu, Xi Zhang 0008 |
EMNLP | 5 |
| 2022 | An efficient hybrid approach based on PSO, ABC and k-means for cluster analysis
Qiumei Pu, Jingkai Gan, Lirong Qiu, Jiaxin Duan |
Multim. Tools Appl. | 3 |
| 2018 | Quantum digital signature for the access control of sensitive data in the big data eraabstractIn our paper we focus on the application of quantum digital signature in the access control of sensitive data such as those data appears in areas like healthcare in order to protect users personal information. There are three parties in our protocol: the signer, the arbitrator and the receiver. Different from most existing protocols developed in arbitrated quantum signature, in which the arbitrator is either assumed to be honest or dishonest, in our protocol we assume the arbitrator is partially honest in the sense that the arbitrator is honest-but-curious. The quantum protocol we propose in this paper have various advantages over existing protocols of the same purpose. The technology we proposed can guarantee the unconditional secure, and it is implementable by the current technology, so the method we proposed can guarantee the security of user’ personal information in the big data era. Lirong Qiu, Feng Cai |
Future Gener. Comput. Syst. | 1 |
| 2018 | Categorical quantum cryptography for access control in cloud computingabstractAccess control is a mechanism that is used to decide which agent has access to which resource with some specific operations. This paper is devoted to the investigation of quantum cryptography in access control. We develop three quantum protocols and use them for key distribution, identity authentication and digital certification, respectively. We analyze our protocols by the graphical language of categorical quantum mechanics. These protocols are unconditionally secure and implementable by the current technology. Lirong Qiu, Xin Sun 0001, Juan Xu 0004 |
Soft Comput. | 1 |
| 2018 | Deontic STIT logic, from logical paradox to security policyabstractA deontic STIT logic is studied in this paper with the possible application of specifying security policies for intrude detection in the pervasive computing environment. Compared to the existing deontic STIT logics, an advantage of our logic is that it is capable of solving the miners paradox, a logical paradox which recently grabs attentions of logicians, philosophers, linguistists and computer scientists. A complete and sound axiomatization of our logic is developed. Lirong Qiu, Xin Sun 0001 |
Soft Comput. | 1 |
| 2018 | Semantic Feature Learning for Heterogeneous Multitask Classification via Non-Negative Matrix FactorizationabstractMultitask learning (MTL) aims to learn multiple related tasks simultaneously instead of separately to improve the generalization performance of each task. Most existing MTL methods assumed that the multiple tasks to be learned have the same feature representation. However, this assumption may not hold for many real-world applications. In this paper, we study the problem of MTL with heterogeneous features for each task. To address this problem, we first construct an integrated graph of a set of bipartite graphs to build a connection among different tasks. We then propose a non-negative matrix factorization-based multitask method (MTNMF) to learn a common semantic feature space underlying different heterogeneous feature spaces of each task. Moreover, an improved version of MTNMF (IMTNMF) is proposed, in which we do not need to construct the correlation matrix between input features and class labels, avoiding the information loss. Finally, based on the common semantic features and original heterogeneous features, we model the heterogenous MTL problem as a multitask multiview learning (MTMVL) problem. In this way, a number of existing MTMVL methods can be applied to solve the problem effectively. Extensive experiments on three real-world problems demonstrate the effectiveness of our proposed methods, and the improved version IMTNMF can gain about 2% average accuracy improvement compared with MTNMF. Fuzhen Zhuang, Xuebing Li, Xin Jin 0004, Lirong Qiu, Qing He 0003 |
IEEE Trans. Cybern. | 5 |
| 2017 | Realizing correlated equilibrium by secure computation
Lirong Qiu, Xin Sun 0001, Xishun Zhao |
J. Inf. Secur. Appl. | 1 |
| 2017 | Implementing RSA for sensor nodes in smart cities
Lirong Qiu, Zhe Liu 0001, Geovandro C. C. F. Pereira, Hwajeong Seo |
Pers. Ubiquitous Comput. | 1 |
| 2007 | Context optimization of AI planning for semantic Web services composition
Lirong Qiu, Liang Chang 0003, Zhongzhi Shi |
Serv. Oriented Comput. Appl. | 1 |
| 2006 | Semantic Web Services Composition Using AI Planning of Description LogicsabstractWeb services composition techniques are gaining momentum as the opportunity to establish reusable and versatile inter-operability applications. The purpose of semantic Web services is to use semantic specification to automate the discovery, invocation, and composition Web services. Description logics is the formalized foundation of semantic Web services and provides well-defined semantics. And many researchers propose their composition approach based on planning techniques. We propose our service composition methods based on description logics and AI planning technologies. Our algorithm for services composition uses backward-chaining search method to find potential candidate services. And we propose a DAG-based method to generate the planning process and filtering the inappropriate services during the DAG generation process. We test our approach on a simple, yet realistic example, and the preliminary results demonstrate that our implementation provides a practical solution Lirong Qiu, Changlin Wan, Zhongzhi Shi |
APSCC | 1 |
| 2006 | Description Logic Based Composition of Web Services
Lirong Qiu, Zhongzhi Shi |
PRIMA | 2 |
| 2005 | An Interval-Based Knowledge Model and Query Language for Temporal Information
Zhongzhi Shi, Xiaoxiao He, Lirong Qiu, Jiewen Luo |
PRIMA | 4 |
| 2005 | Ontology-Driven Knowledge Management on the GridabstractThe combination of large data set size, geographic distribution of resources and users, and sophisticated applications on data and information needs robust infrastructures. In this paper, knowledge management sphere (KMSphere) is proposed and developed to explore important aspects of service-oriented and ontology-driven knowledge management on the grid. The main idea of KMSphere is to integrate ontologies with a service-oriented grid, build a knowledge space on top of databases, and then organize, utilize, and manage the knowledge resources in that space. Zhongzhi Shi, Lirong Qiu |
Web Intelligence | 3 |