VLDB 2026 Research / reviewers in the wild / expert
Xingyu Zhao 0001
dblp:83/504-1
· DBLP profile ↗
35ranked-venue papers
9as first author
28since 2021 · last 2026
0000-0002-3474-349XORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 19 · 2 first-author · 18 since 2021Software engineering, systems software and programming languages · 10 · 5 first-author · 5 since 2021Graphics, computer vision, multimedia, augmented reality and games · 8 · 1 first-author · 7 since 2021Systems, architecture and hardware · 4 · 4 since 2021Security and privacy · 3 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Fragile by Design: On the Limits of Adversarial Defenses in Personalized DreamBooth GenerationabstractPersonalized AI applications such as DreamBooth enable the generation of customized content from user images, but also raise significant privacy concerns, particularly the risk of facial identity leakage. Recent defense mechanisms like Anti-DreamBooth attempt to mitigate this risk by injecting adversarial perturbations into user photos to prevent successful personalization. However, we identify two critical yet overlooked limitations of these methods. First, the adversarial examples often exhibit perceptible artifacts such as conspicuous patterns or stripes, making them easily detectable as manipulated content. Second, the perturbations are highly fragile, as even a simple, non-learned filter can effectively remove them, thereby restoring the model's ability to memorize and reproduce user identity. To investigate this vulnerability, we propose a novel evaluation framework, AntiDB_Purify, to systematically evaluate existing defenses under realistic purification threats, including both traditional image filters and adversarial purification. Results reveal that none of the current methods maintains their protective effectiveness under such threats. These findings highlight that current defenses offer a false sense of security and underscore the urgent need for more imperceptible and robust protections to safeguard user identity in personalized generation. Yi Zhang 0141, Xiangyu Yin 0001, Chengxuan Qin, Xingyu Zhao 0001, Xiaowei Huang 0001, Wenjie Ruan |
AAAI | 5 |
| 2026 | Uncertainty-Aware Measurement of Scenario Suite Representativeness for Autonomous Systems
Robab Aghazadeh Chakherlou, Siddartha Khastgir, Xingyu Zhao 0001, Jerein Jeyachandran, Shufeng Chen |
IV | 3 |
| 2026 | Quantifying Fidelity: A Decisive Feature Approach to Comparing Synthetic and Real ImageryabstractVirtual testing using synthetic data has become a cornerstone of autonomous vehicle (AV) safety assurance. Despite progress in improving visual realism through advanced simulators and generative AI, recent studies reveal that pixel-level fidelity alone does not ensure reliable transfer from simulation to the real world. What truly matters is whether the system-under-test (SUT) bases its decisions on consistent decision evidence in both real and simulated environments, not just whether images "look real" to humans. To this end this paper proposes a behavior-grounded fidelity measure by introducing Decisive Feature Fidelity (DFF), a new SUT-specific metric that extends the existing fidelity spectrum to capture mechanism parity, that is, agreement in the model-specific decisive evidence that drives the SUT's decisions across domains. DFF leverages explainable-AI methods to identify and compare the decisive features driving the SUT's outputs for matched real-synthetic pairs. We further propose estimators based on counterfactual explanations, along with a DFF-guided calibration scheme to enhance simulator fidelity. Experiments on 2126 matched KITTI-VirtualKITTI2 pairs demonstrate that DFF reveals discrepancies overlooked by conventional output-value fidelity. Furthermore, results show that DFF-guided calibration improves decisive-feature and input-level fidelity without sacrificing output value fidelity across diverse SUTs. Danial Safaei, Siddartha Khastgir, Mohsen Alirezaei, Jeroen Ploeg, Chih-Hong Cheng, Son Tong, Xingyu Zhao 0001 |
IV | 7 |
| 2025 | Risk Controlled Image RetrievalabstractMost image retrieval research prioritizes improving predictive performance, often overlooking situations where the reliability of predictions is equally important. The gap between model performance and reliability requirements highlights the need for a systematic approach to analyze and address the risks associated with image retrieval. Uncertainty quantification technique can be applied to mitigate this issue by assessing uncertainty for retrieval sets, but it provides only a heuristic estimate of uncertainty rather than a guarantee. To address these limitations, we present Risk Controlled Image Retrieval (RCIR), which generates retrieval sets with coverage guarantee, i.e., retrieval sets that are guaranteed to contain the true nearest neighbors with a predefined probability. RCIR can be easily integrated with existing uncertainty-aware image retrieval systems, agnostic to data distribution and model selection. To the best of our knowledge, this is the first work that provides coverage guarantees to image retrieval. The validity and efficiency of RCIR are demonstrated on four real-world datasets: CAR-196, CUB-200, Pittsburgh, and ChestX-Det. Kaiwen Cai, Xiaoxuan Lu 0001, Xingyu Zhao 0001, Wei Huang 0035, Xiaowei Huang 0001 |
AAAI | 3 |
| 2025 | The Impact of Live Polling Quizzes on Student Engagement and Performance in Computer Science Lectures: A Post-COVID19 StudyabstractBefore COVID19, live polling and real-time feedback tools gained popularity in higher education for enhancing student engagement, boosting attention, participation, and understanding of course materials. However, recent changes in learning behaviours due to the pandemic necessitate a reevaluation of these active learning technologies. In this context, our study focuses on the Computer Science (CS) domain, investigating the impact of Live Polling Quizzes (LPQs) in undergraduate CS lectures. These quizzes comprise fact-based, formally defined questions with clear answers, aiming to enhance engagement, learning outcomes, and overall perceptions of the course module. A survey was conducted among 70 undergraduate CS students, attending CS modules with and without LPQs. The results revealed that, while LPQs contribute to lecture attendance, additional factors likely play a larger role in attendance rates. Students generally find LPQs beneficial for understanding content, maintaining attention, and fostering motivation, but also viewing them as essential for re-establishing peer and instructor connections post-pandemic. Students prefer a balanced LPQ frequency and clear, accessible instructions, reflecting a reliance on digital tools and self-paced engagement habits developed during remote learning. Xingyu Zhao 0001 |
CSEDU (1) | 1 |
| 2025 | SIDA: Social Media Image Deepfake Detection, Localization and Explanation with Large Multimodal ModelabstractThe rapid advancement of generative models in creating highly realistic images poses substantial risks for misinformation dissemination. For instance, a synthetic image, when shared on social media, can mislead extensive audiences and erode trust in digital content, resulting in severe repercussions. Despite some progress, academia has not yet created a large and diversified deepfake detection dataset for social media, nor has it devised an effective solution to address this issue. In this paper, we introduce the Social media Image Detection dataSet (SID-Set), which offers three key advantages: (1) extensive volume, featuring 300K AI-generated/tampered and authentic images with comprehensive annotations, (2) broad diversity, encompassing fully synthetic and tampered images across various classes, and (3) elevated realism, with images that are predominantly indistinguishable from genuine ones through mere visual inspection. Furthermore, leveraging the exceptional capabilities of large multimodal models, we propose a new image deepfake detection, localization, and explanation framework, named SIDA (Social media Image Detection, localization, and explanation Assistant). SIDA not only discerns the authenticity of images, but also delineates tampered regions through mask prediction and provides textual explanations of the model’s judgment criteria. Compared with state-of-the-art deepfake detection models on SID-Set and other benchmarks, extensive experiments demonstrate that SIDA achieves superior performance among diversified settings. The code, model, and dataset will be released. Zhenglin Huang, Jinwei Hu 0001, Xiangtai Li, Yiwei He, Xingyu Zhao 0001, Bei Peng 0001, Baoyuan Wu, Xiaowei Huang 0001 |
CVPR | 5 |
| 2025 | Adversarial Training for Probabilistic Robustness
Yi Zhang 0141, Wenjie Ruan, Xiaowei Huang 0001, Siddartha Khastgir, Xingyu Zhao 0001 |
ICCV | 7 |
| 2025 | Interpreting Safety: A LLM and STPA Approach
Shufeng Chen, Xiangyu Yin 0001, Wenjie Ruan, Siddartha Khastgir, Ji Ruan, Xingyu Zhao 0001, Xiaowei Huang 0001 |
PRICAI (4) | 7 |
| 2025 | Runtime Monitoring and Enforcement of Conditional Fairness in Generative AIs
Chih-Hong Cheng, Changshun Wu, Xingyu Zhao 0001, Saddek Bensalem, Harald Ruess |
RV | 3 |
| 2024 | Representation-Based Robustness in Goal-Conditioned Reinforcement LearningabstractWhile Goal-Conditioned Reinforcement Learning (GCRL) has gained attention, its algorithmic robustness against adversarial perturbations remains unexplored. The attacks and robust representation training methods that are designed for traditional RL become less effective when applied to GCRL. To address this challenge, we first propose the Semi-Contrastive Representation attack, a novel approach inspired by the adversarial contrastive attack. Unlike existing attacks in RL, it only necessitates information from the policy function and can be seamlessly implemented during deployment. Then, to mitigate the vulnerability of existing GCRL algorithms, we introduce Adversarial Representation Tactics, which combines Semi-Contrastive Adversarial Augmentation with Sensitivity-Aware Regularizer to improve the adversarial robustness of the underlying RL agent against various types of perturbations. Extensive experiments validate the superior performance of our attack and defence methods across multiple state-of-the-art GCRL algorithms. Our code is available at https://github.com/TrustAI/ReRoGCRL. Xiangyu Yin 0001, Sihao Wu, Jiaxu Liu 0001, Xingyu Zhao 0001, Xiaowei Huang 0001, Wenjie Ruan |
AAAI | 5 |
| 2024 | Is Difficulty Calibration All We Need? Towards More Practical Membership Inference AttacksabstractThe vulnerability of machine learning models to Membership Inference Attacks (MIAs) has garnered considerable attention in recent years. These attacks determine whether a data sample belongs to the model's training set or not. Recent research has focused on reference-based attacks, which leverage difficulty calibration with independently trained reference models. While empirical studies have demonstrated its effectiveness, there is a notable gap in our understanding of the circumstances under which it succeeds or fails. In this paper, we take a further step towards a deeper understanding of the role of difficulty calibration. Our observations reveal inherent limitations in calibration methods, leading to the misclassification of non-members and suboptimal performance, particularly on high-loss samples. We further identify that these errors stem from an imperfect sampling of the potential distribution and a strong dependence of membership scores on the model parameters. By shedding light on these issues, we propose RAPID: a query-efficient and computation-efficient MIA that directly Re-leverAges the original membershiP scores to mItigate the errors in Difficulty calibration. Our experimental results, spanning 9 datasets and 5 model architectures, demonstrate that RAPID outperforms previous state-of-the-art attacks (e.g., LiRA and Canary offline) across different metrics while remaining computationally efficient. Our observations and analysis challenge the current de facto paradigm of difficulty calibration in high-precision inference, encouraging greater attention to the persistent risks posed by MIAs in more practical scenarios. Yu He 0009, Boheng Li, Mengda Yang, Juan Wang 0006, Hongxin Hu, Xingyu Zhao 0001 |
CCS | 7 |
| 2024 | ProTIP: Probabilistic Robustness Verification on Text-to-Image Diffusion Models Against Stochastic Perturbation
Yi Zhang 0141, Yun Tang 0003, Wenjie Ruan, Xiaowei Huang 0001, Siddartha Khastgir, Paul A. Jennings, Xingyu Zhao 0001 |
ECCV (32) | 7 |
| 2024 | Position: Building Guardrails for Large Language Models Requires Systematic DesignabstractAs Large Language Models (LLMs) become more integrated into our daily lives, it is crucial to identify and mitigate their risks, especially when the risks can have profound impacts on human users and societies. Guardrails, which filter the inputs or outputs of LLMs, have emerged as a core safeguarding technology. This position paper takes a deep look at current open-source solutions (Llama Guard, Nvidia NeMo, Guardrails AI), and discusses the challenges and the road towards building more complete solutions. Drawing on robust evidence from previous research, we advocate for a systematic approach to construct guardrails for LLMs, based on comprehensive consideration of diverse contexts across various LLMs applications. We propose employing socio-technical methods through collaboration with a multi-disciplinary team to pinpoint precise technical requirements, exploring advanced neural-symbolic implementations to embrace the complexity of the requirements, and developing verification and testing to ensure the utmost quality of the final product. Yi Dong 0002, Ronghui Mu, Gaojie Jin, Jinwei Hu 0001, Xingyu Zhao 0001, Wenjie Ruan, Xiaowei Huang 0001 |
ICML | 6 |
| 2024 | Data Augmentation for Continual RL via Adversarial Gradient Episodic Memory
Sihao Wu, Xingyu Zhao 0001, Xiaowei Huang 0001 |
ICONIP (4) | 2 |
| 2024 | ODD-based Query-time Scenario Mutation Framework for Autonomous Driving Scenario databasesabstractLarge-scale scenario databases may contain hundreds of thousands of scenarios for the verification and validation (V&V) of autonomous vehicles (AV). Scenarios in the database are often labelled with semantic Operational Design Domain (ODD) tags (e.g., WeatherRainy, RoadTypeHighway and ActorTypeTruck) to be queried via exact tag matching. Such a scenario database design has two major limitations, i.e. combinatorial scenario generation inevitably leads to many redundant scenarios, and each ODD query matches only a small number of scenarios in the database (0.2% in our case study), rendering most of the database wealth wasted. We propose a novel scenario database design and the first ODD-based query-time scenario mutation framework to address the limitations. Our case study results show that the proposed framework has the potential to fully utilize all the database scenarios at query time while eliminating scenario redundancy in the database (in our case study, given the same ODD query, the number of final matched scenarios increased by 36 times, diversity increased by 99 times, and scenario database utilization rate increased from 0.2% to 36%). Yun Tang 0003, Dhanush Raj, Xingyu Zhao 0001, Antonio Anastasio Bruto da Costa, Siddartha Khastgir, Paul A. Jennings |
ICRA | 3 |
| 2024 | Augmenting Scenario Description Languages for Intelligence Testing of Automated Driving SystemsabstractScenario-based verification and validation (V&V) has emerged as the predominant approach for the performance evaluation of automated driving systems (ADSs). Many scenario-generation methods have been proposed to search for critical scenarios, i.e. disengagement or traffic rule violations. However, the widely adopted binary (pass/fail) criterion suffers from two main limitations, i.e., the difficulty of locating root causes and the lack of statistical guarantee of testing sufficiency. Recently, new scenario engineering approaches focusing on the intelligence of ADSs enlightened a promising pathway via dynamic driving task decomposition and function atom constraints. However, none of the state-of-the-art scenario description languages support such approaches. To fill this gap and facilitate further research into this promising direction, in this work, we propose a generic architecture to extend the existing scenario description languages for the intelligence testing of ADSs. The case study with WMG SDL demonstrates the capability and flexibility of the proposed extension design in defining intelligence function constraints. Yun Tang 0003, Antonio Anastasio Bruto da Costa, Patrick Irvine, Tudor Dodoiu, Yi Zhang 0141, Xingyu Zhao 0001, Siddartha Khastgir, Paul A. Jennings |
IV | 6 |
| 2024 | TARP-VP: Towards Evaluation of Transferred Adversarial Robustness and Privacy on Label Mapping Visual Prompting ModelsabstractAdversarial robustness and privacy of deep learning (DL) models are two widely studied topics in AI security. Adversarial training (AT) is
an effective approach to improve the robustness of DL models against adversarial attacks. However, while models with AT demonstrate enhanced robustness, they become more susceptible to membership inference attacks (MIAs), thus increasing the risk of privacy leakage. This indicates a negative trade-off between adversarial robustness and privacy in general deep learning models. Visual prompting is a novel model reprogramming (MR) technique used for fine-tuning pre-trained models, achieving good performance in vision tasks, especially when combined with the label mapping technique. However, the performance of label-mapping-based visual prompting (LM-VP) under adversarial attacks and MIAs lacks evaluation. In this work, we regard the MR of LM-VP as a unified entity, referred to as the LM-VP model, and take a step toward jointly evaluating the adversarial robustness and privacy of LM-VP models. Experimental results show that
the choice of pre-trained models significantly affects the white-box adversarial robustness of LM-VP, and standard AT even substantially degrades its performance. In contrast, transfer AT-trained LM-VP achieves a good trade-off between transferred adversarial robustness and privacy, a finding that has been consistently validated across various pre-trained models. Yi Zhang 0141, Xingyu Zhao 0001, Xiaowei Huang 0001, Wenjie Ruan |
NeurIPS | 4 |
| 2024 | Bridging formal methods and machine learning with model checking and global optimisationabstractFormal methods and machine learning are two research fields with drastically different foundations and philosophies. Formal methods utilise mathematically rigorous techniques for software and hardware systems' specification, development and verification. Machine learning focuses on pragmatic approaches to gradually improve a parameterised model by observing a training data set. While historically, the two fields lack communication, this trend has changed in the past few years with an outburst of research interest in the robustness verification of neural networks. This paper will briefly review these works, and focus on the urgent need for broader and more in-depth communication between the two fields, with the ultimate goal of developing learning-enabled systems with excellent performance and acceptable safety and security. We present a specification language, MLS2, and show that it can express a set of known safety and security properties, including generalisation, uncertainty, robustness, data poisoning, backdoor, model stealing, membership inference, model inversion, interpretability, and fairness. To verify MLS2 properties, we promote the global optimisation-based methods, which have provable guarantees on the convergence to the optimal solution. Many of them have theoretical bounds on the gap between current solutions and the optimal solution. Saddek Bensalem, Xiaowei Huang 0001, Wenjie Ruan, Qiyi Tang 0001, Changshun Wu, Xingyu Zhao 0001 |
J. Log. Algebraic Methods Program. | 6 |
| 2024 | Hierarchical Distribution-aware Testing of Deep LearningabstractWith its growing use in safety/security-critical applications, Deep Learning (DL) has raised increasing concerns regarding its dependability. In particular, DL has a notorious problem of lacking robustness. Input added with adversarial perturbations, i.e., Adversarial Examples (AEs) , are easily mispredicted by the DL model. Despite recent efforts made in detecting AEs via state-of-the-art attack and testing methods, they are normally input distribution–agnostic and/or disregard the perceptual quality of adversarial perturbations. Consequently, the detected AEs are irrelevant inputs in the application context or noticeably unrealistic to humans. This may lead to a limited effect on improving the DL model’s dependability, as the testing budget is likely to be wasted on detecting AEs that are encountered very rarely in its real-life operations. In this article, we propose a new robustness testing approach for detecting AEs that considers both the feature-level distribution and the pixel-level distribution, capturing the perceptual quality of adversarial perturbations. The two considerations are encoded by a novel hierarchical mechanism. First, we select test seeds based on the density of feature-level distribution and the vulnerability of adversarial robustness. The vulnerability of test seeds is indicated by the auxiliary information, which are highly correlated with local robustness. Given a test seed, we then develop a novel genetic algorithm–based local test case generation method, in which two fitness functions work alternatively to control the perceptual quality of detected AEs. Finally, extensive experiments confirm that our holistic approach considering hierarchical distributions is superior to the state-of-the-arts that either disregard any input distribution or only consider a single (non-hierarchical) distribution, in terms of not only detecting imperceptible AEs but also improving the overall robustness of the DL model under testing. Wei Huang 0035, Xingyu Zhao 0001, Alec Banks, Victoria Cox, Xiaowei Huang 0001 |
ACM Trans. Softw. Eng. Methodol. | 2 |
| 2023 | SAFARI: Versatile and Efficient Evaluations for Robustness of InterpretabilityabstractInterpretability of Deep Learning (DL) is a barrier to trustworthy AI. Despite great efforts made by the Explainable AI (XAI) community, explanations lack robustness— indistinguishable input perturbations may lead to different XAI results. Thus, it is vital to assess how robust DL interpretability is, given an XAI method. In this paper, we identify several challenges that the state-of-the-art is unable to cope with collectively: i) existing metrics are not comprehensive; ii) XAI techniques are highly heterogeneous; iii) misinterpretations are normally rare events. To tackle these challenges, we introduce two black-box evaluation methods, concerning the worst-case interpretation discrepancy and a probabilistic notion of how robust in general, respectively. Genetic Algorithm (GA) with bespoke fitness function is used to solve constrained optimisation for efficient worst-case evaluation. Subset Simulation (SS), dedicated to estimate rare event probabilities, is used for evaluating overall robustness. Experiments show that the accuracy, sensitivity, and efficiency of our methods outperform the state-of-the-arts. Finally, we demonstrate two applications of our methods: ranking robust XAI methods and selecting training schemes to improve both classification and interpretation robustness. Wei Huang 0035, Xingyu Zhao 0001, Gaojie Jin, Xiaowei Huang 0001 |
ICCV | 2 |
| 2023 | Reliability Assessment and Safety Arguments for Machine Learning Components in System AssuranceabstractThe increasing use of Machine Learning (ML) components embedded in autonomous systems—so-called Learning-Enabled Systems (LESs)—has resulted in the pressing need to assure their functional safety. As for traditional functional safety, the emerging consensus within both, industry and academia, is to use assurance cases for this purpose. Typically assurance cases support claims of reliability in support of safety, and can be viewed as a structured way of organising arguments and evidence generated from safety analysis and reliability modelling activities. While such assurance activities are traditionally guided by consensus-based standards developed from vast engineering experience, LESs pose new challenges in safety-critical application due to the characteristics and design of ML models. In this article, we first present an overall assurance framework for LESs with an emphasis on quantitative aspects, e.g., breaking down system-level safety targets to component-level requirements and supporting claims stated in reliability metrics. We then introduce a novel model-agnostic Reliability Assessment Model (RAM) for ML classifiers that utilises the operational profile and robustness verification evidence. We discuss the model assumptions and the inherent challenges of assessing ML reliability uncovered by our RAM and propose solutions to practical use. Probabilistic safety argument templates at the lower ML component-level are also developed based on the RAM. Finally, to evaluate and demonstrate our methods, we not only conduct experiments on synthetic/benchmark datasets but also scope our methods with case studies on simulated Autonomous Underwater Vehicles and physical Unmanned Ground Vehicles. Yi Dong 0002, Wei Huang 0035, Vibhav Bharti, Victoria Cox, Alec Banks, Sen Wang 0002, Xingyu Zhao 0001, Sven Schewe, Xiaowei Huang 0001 |
ACM Trans. Embed. Comput. Syst. | 7 |
| 2023 | The Unnecessity of Assuming Statistically Independent Tests in Bayesian Software Reliability AssessmentsabstractWhen assessing a software-based system, the results of Bayesian statistical inference on operational testing data can provide strong support for software reliability claims. For inference, this data (i.e., software successes and failures) is often assumed to arise in an independent, identically distributed (i.i.d.) manner. In this paper we show how conservative Bayesian approaches make this assumption unnecessary, by incorporating one's doubts about the assumption into the assessment. We derive conservative confidence bounds on a system's probability of failure on demand (pfd), when operational testing reveals no failures. The generality and utility of the confidence bounds are illustrated in the assessment of a nuclear power-plant safety-protection system, under varying levels of skepticism about the i.i.d. assumption. The analysis suggests that the i.i.d. assumption can make Bayesian reliability assessments extremely optimistic – such assessments do not explicitly account for how software can be very likely to exhibit no failures during extensive operational testing despite the software'spfdbeing undesirably large. Kizito Salako, Xingyu Zhao 0001 |
IEEE Trans. Software Eng. | 2 |
| 2022 | Bridging Formal Methods and Machine Learning with Global Optimisation
Xiaowei Huang 0001, Wenjie Ruan, Qiyi Tang 0001, Xingyu Zhao 0001 |
ICFEM | 4 |
| 2022 | Dependability Analysis of Deep Reinforcement Learning based Robotics and Autonomous Systems through Probabilistic Model CheckingabstractWhile Deep Reinforcement Learning (DRL) provides transformational capabilities to the control of Robotics and Autonomous Systems (RAS), the black-box nature of DRL and uncertain deployment environments of RAS pose new challenges on its dependability. Although existing works impose constraints on the DRL policy to ensure successful completion of the mission, it is far from adequate to assess the DRL-driven RAS in a holistic way considering all dependability properties. In this paper, we formally define a set of dependability properties in temporal logic and construct a Discrete-Time Markov Chain (DTMC) to model the dynamics of risk/failures of a DRL-driven RAS interacting with the stochastic environment. We then conduct Probabilistic Model Checking (PMC) on the designed DTMC to verify those properties. Our experimental results show that the proposed method is effective as a holistic assessment framework while uncovering conflicts between the properties that may need trade-offs in training. Moreover, we find that the standard DRL training cannot improve dependability properties, thus requiring bespoke optimisation objectives. Finally, our method offers sensitivity analysis of dependability properties to disturbance levels from environments, providing insights for the assurance of real RAS. Yi Dong 0002, Xingyu Zhao 0001, Xiaowei Huang 0001 |
IROS | 2 |
| 2022 | Embedding and extraction of knowledge in tree ensemble classifiersabstractAbstract The embedding and extraction of knowledge is a recent trend in machine learning applications, e.g., to supplement training datasets that are small. Whilst, as the increasing use of machine learning models in security-critical applications, the embedding and extraction of malicious knowledge are equivalent to the notorious backdoor attack and defence, respectively. This paper studies the embedding and extraction of knowledge in tree ensemble classifiers, and focuses on knowledge expressible with a generic form of Boolean formulas, e.g., point-wise robustness and backdoor attacks. For the embedding, it is required to bepreservative(the original performance of the classifier is preserved),verifiable(the knowledge can be attested), andstealthy(the embedding cannot be easily detected). To facilitate this, we propose two novel, and effective embedding algorithms, one of which is for black-box settings and the other for white-box settings. The embedding can be done inPTIME. Beyond the embedding, we develop an algorithm to extract the embedded knowledge, by reducing the problem to be solvable with an SMT (satisfiability modulo theories) solver. While this novel algorithm can successfully extract knowledge, the reduction leads to anNPcomputation. Therefore, if applying embedding as backdoor attacks and extraction as defence, our results suggest a complexity gap (P vs. NP) between the attack and defence when working with tree ensemble classifiers. We apply our algorithms to a diverse set of datasets to validate our conclusion extensively. Wei Huang 0035, Xingyu Zhao 0001, Xiaowei Huang 0001 |
Mach. Learn. | 2 |
| 2022 | Coverage-Guided Testing for Recurrent Neural NetworksabstractRecurrent neural networks (RNNs) have been applied to a broad range of applications, including natural language processing, drug discovery, and video recognition. Their vulnerability to input perturbation is also known. Aligning with a view from software defect detection, this article aims to develop a coverage-guided testing approach to systematically exploit the internal behavior of RNNs, with the expectation that such testing can detect defects with high possibility. Technically, the long short-term memory network (LSTM), a major class of RNNs, is thoroughly studied. A family of three test metrics are designed to quantify not only the values but also the temporal relations (including both stepwise and bounded-length) exhibited when LSTM processing inputs. A genetic algorithm is applied to efficiently generate test cases. The test metrics and test case generation algorithm are implemented into a tooltestRNN, which is then evaluated on a set of LSTM benchmarks. Experiments confirm thattestRNNhas advantages over the state-of-the-art tool DeepStellar and attack-based defect detection methods, owing to its working with finer temporal semantics and the consideration of the naturalness of input perturbation. Furthermore,testRNNenables meaningful information to be collected and exhibited for users to understand the testing results, which is an important step toward interpretable neural network testing. Wei Huang 0035, Youcheng Sun, Xingyu Zhao 0001, James Sharp, Wenjie Ruan, Xiaowei Huang 0001 |
IEEE Trans. Reliab. | 3 |
| 2021 | Conservative Confidence Bounds in Safety, from Generalised Claims of Improvement & Statistical Evidenceabstract“Proven-in-use”, “globally-at-least-equivalent”, “stress-tested”, are concepts that come up in diverse contexts in acceptance, certification or licensing of critical systems. Their common feature is that dependability claims for a system in a certain operational environment are supported, in part, by evidence – viz of successful operation – concerning different, though related, system[s] and/or environment[s], together with an auxiliary argument that the target system/environment offers the same, or improved, safety. We propose a formal probabilistic (Bayesian) organisation for these arguments. Through specific examples of evidence for the “improvement” argument above, we demonstrate scenarios in which formalising such arguments substantially increases confidence in the target system, and show why this is not always the case. Example scenarios concern vehicles and nuclear plants. Besides supporting stronger claims, the mathematical formalisation imposes precise statements of the bases for “improvement” claims: seemingly similar forms of prior beliefs are sometimes revealed to imply substantial differences in the claims they can support. Kizito Salako, Lorenzo Strigini, Xingyu Zhao 0001 |
DSN | 3 |
| 2021 | BayLIME: Bayesian local interpretable model-agnostic explanationsabstractGiven the pressing need for assuring algorithmic transparency, Explainable AI (XAI) has emerged as one of the key areas of AI research. In this paper, we develop a novel Bayesian extension to the LIME framework, one of the most widely used approaches in XAI – which we call BayLIME. Compared to LIME, BayLIME exploits prior knowledge and Bayesian reasoning to improve both the consistency in repeated explanations of a single prediction and the robustness to kernel settings. BayLIME also exhibits better explanation fidelity than the state-of-the-art (LIME, SHAP and GradCAM) by its ability to integrate prior knowledge from, e.g., a variety of other XAI techniques, as well as verification and validation (V&V) methods. We demonstrate the desirable properties of BayLIME through both theoretical analysis and extensive experiments. Xingyu Zhao 0001, Wei Huang 0035, Xiaowei Huang 0001, Valentin Robu, David Flynn |
UAI | 1 |
| 2020 | Interval Change-Point Detection for Runtime Probabilistic Model CheckingabstractRecent probabilistic model checking techniques can verify reliability and performance properties of software systems affected by parametric uncertainty. This involves modelling the system behaviour using interval Markov chains, i.e., Markov models with transition probabilities or rates specified as intervals. These intervals can be updated continually using Bayesian estimators with imprecise priors, enabling the verification of the system properties of interest at runtime. However, Bayesian estimators are slow to react to sudden changes in the actual value of the estimated parameters, yielding inaccurate intervals and leading to poor verification results after such changes. To address this limitation, we introduce an efficient interval change-point detection method, and we integrate it with a state-of-the-art Bayesian estimator with imprecise priors. Our experimental results show that the resulting end-to-end Bayesian approach to change-point detection and estimation of interval Markov chain parameters handles effectively a wide range of sudden changes in parameter values, and supports runtime probabilistic model checking under parametric uncertainty. Xingyu Zhao 0001, Radu Calinescu, Simos Gerasimou, Valentin Robu, David Flynn |
ASE | 1 |
| 2020 | A Safety Framework for Critical Systems Utilising Deep Neural Networks
Xingyu Zhao 0001, Alec Banks, James Sharp, Valentin Robu, David Flynn, Michael Fisher 0001, Xiaowei Huang 0001 |
SAFECOMP | 1 |
| 2020 | Assessing safety-critical systems from operational testing: A study on autonomous vehiclesabstractDemonstrating high reliability and safety for safety-critical systems (SCSs) remains a hard problem. Diverse evidence needs to be combined in a rigorous way: in particular, results of operational testing with other evidence from design and verification. Growing use of machine learning in SCSs, by precluding most established methods for gaining assurance, makes evidence from operational testing even more important for supporting safety and reliability claims. We revisit the problem of using operational testing to demonstrate high reliability. We use Autonomous Vehicles (AVs) as a current example. AVs are making their debut on public roads: methods for assessing whether an AV is safe enough are urgently needed. We demonstrate how to answer 5 questions that would arise in assessing an AV type, starting with those proposed by a highly-cited study. We apply new theorems extending our Conservative Bayesian Inference (CBI) approach, which exploit the rigour of Bayesian methods while reducing the risk of involuntary misuse associated (we argue) with now-common applications of Bayesian inference; we define additional conditions needed for applying these methods to AVs. Prior knowledge can bring substantial advantages if the AV design allows strong expectations of safety before road testing. We also show how naive attempts at conservative assessment may lead to over-optimism instead; why extrapolating the trend of disengagements (take-overs by human drivers) is not suitable for safety claims; use of knowledge that an AV has moved to a “less stressful” environment. While some reliability targets will remain too high to be practically verifiable, our CBI approach removes a major source of doubt: it allows use of prior knowledge without inducing dangerously optimistic biases. For certain ranges of required reliability and prior beliefs, CBI thus supports feasible, sound arguments. Useful conservative claims can be derived from limited prior knowledge. Xingyu Zhao 0001, Kizito Salako, Lorenzo Strigini, Valentin Robu, David Flynn |
Inf. Softw. Technol. | 1 |
| 2019 | Probabilistic Model Checking of Robots Deployed in Extreme EnvironmentsabstractRobots are increasingly used to carry out critical missions in extreme environments that are hazardous for humans. This requires a high degree of operational autonomy under uncertain conditions, and poses new challenges for assuring the robot’s safety and reliability. In this paper, we develop a framework for probabilistic model checking on a layered Markov model to verify the safety and reliability requirements of such robots, both at pre-mission stage and during runtime. Two novel estimators based on conservative Bayesian inference and imprecise probability model with sets of priors are introduced to learn the unknown transition parameters from operational data. We demonstrate our approach using data from a real-world deployment of unmanned underwater vehicles in extreme environments. Xingyu Zhao 0001, Valentin Robu, David Flynn, Fateme Dinmohammadi, Michael Fisher 0001, Matthew P. Webster |
AAAI | 1 |
| 2019 | Assessing the Safety and Reliability of Autonomous Vehicles from Road TestingabstractThere is an urgent societal need to assess whether autonomous vehicles (AVs) are safe enough. From published quantitative safety and reliability assessments of AVs, we know that, given the goal of predicting very low rates of accidents, road testing alone requires infeasible numbers of miles to be driven. However, previous analyses do not consider any knowledge prior to road testing - knowledge which could bring substantial advantages if the AV design allows strong expectations of safety before road testing. We present the advantages of a new variant of Conservative Bayesian Inference (CBI), which uses prior knowledge while avoiding optimistic biases. We then study the trend of disengagements (take-overs by human drivers) by applying Software Reliability Growth Models (SRGMs) to data from Waymo's public road testing over 51 months, in view of the practice of software updates during this testing. Our approach is to not trust any specific SRGM, but to assess forecast accuracy and then improve forecasts. We show that, coupled with accuracy assessment and recalibration techniques, SRGMs could be a valuable test planning aid. Xingyu Zhao 0001, Valentin Robu, David Flynn, Kizito Salako, Lorenzo Strigini |
ISSRE | 1 |
| 2019 | Towards Integrating Formal Verification of Autonomous Robots with Battery Prognostics and Health Management
Xingyu Zhao 0001, Matthew Osborne, Jenny Lantair, Valentin Robu, David Flynn, Xiaowei Huang 0001, Michael Fisher 0001, Fabio Papacchini, Angelo Ferrando 0001 |
SEFM | 1 |
| 2015 | Conservative claims about the probability of perfection of software-based systemsabstractIn recent years we have become interested in the problem of assessing the probability of perfection of software-based systems which are sufficiently simple that they are "possibly perfect". By "perfection" we mean that the software of interest will never fail in a specific operating environment. We can never be certain that it is perfect, so our interest lies in claims for its probability of perfection. Our approach is Bayesian: our aim is to model the changes to this probability of perfection as we see evidence of failure-free working. Much of the paper considers the difficult problem of expressing prior beliefs about the probability of failure on demand (pfd), and representing these mathematically. This requires the assessor to state his prior belief in perfection as a probability, and also to state what he believes are likely values of the pfd in the event that the system is not perfect. We take the view that it will be impractical for an assessor to express these beliefs as a complete distribution for pfd. Our approach to the problem has three threads. Firstly we assume that, although he cannot provide a full probabilistic description of his uncertainty in a single distribution, the assessor can express some precise but partial beliefs about the unknowns. Secondly, we assume that in the inevitable presence of such incompleteness, the Bayesian analysis needs to provide results that are guaranteed to be conservative (because the analyses we have in mind relate to critical systems). Finally, we seek to prune the set of prior distributions that the assessor finds acceptable in order that the conservatism of the results is no greater than it has to be, i.e. we propose, and eliminate, sets of priors that would appear generally unreasonable. We give some illustrative numerical examples of this approach, and note that the numerical values obtained for the posterior probability of perfection in this way seem potentially useful (although we make no claims for the practical realism of the numbers we use). We also note that the general approach here to the problem of expressing and using limited prior belief in a Bayesian analysis may have wider applicability than to the problem we have addressed. Xingyu Zhao 0001, Bev Littlewood, Andrey Povyakalo, David Wright 0001 |
ISSRE | 1 |