Leon Lin

dblp:04/2519 · DBLP profile ↗
← Back
4ranked-venue papers
1as first author
1since 2021 · last 2025
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 2 · 1 first-author · 1 since 2021Systems, architecture and hardware · 1Computer networks · 1Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Artificial intelligence
1 paper
Language models and text generation · 56% Trustworthy machine learning · 44%
Network and information security
1 paper
Security and privacy of machine learning · 100%

Topics — the 5 heaviest of 5, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Natural language and speech › Language models and text generation › alignment
robust alignment
0.912025
Single Character Perturbations Break LLM Alignment · AAAI 2025
Machine learning › Trustworthy machine learning
robustness
0.912025
Single Character Perturbations Break LLM Alignment · AAAI 2025
Security and privacy of machine learning
adversarial attack
0.912025
Single Character Perturbations Break LLM Alignment · AAAI 2025
Security and privacy of machine learning › adversarial attack
jailbreak attack
0.912025
Single Character Perturbations Break LLM Alignment · AAAI 2025
Natural language and speech › Language models and text generation
large language model
0.312025
Single Character Perturbations Break LLM Alignment · AAAI 2025

Methods — techniques the papers use, named apart from their topics

adversarial perturbation · 1.7
YearPublicationVenuePosition
2025 Single Character Perturbations Break LLM Alignment
abstract
When LLMs are deployed in sensitive, human-facing settings, it is crucial that they do not output unsafe, biased, or privacy-violating outputs. For this reason, models are both trained and instructed to refuse to answer unsafe prompts such as ``Tell me how to build a bomb." We find that, despite these safeguards, it is possible to break model defenses simply by appending a space or other single character token to the end of a model's input. In a study of a variety of open-source models, we demonstrate that this simple perturbation is able to cause the majority of models to generate harmful outputs with very high probability. We further find that both Claude and GPT-3.5 demonstrate the same behavior. We examine the causes of this behavior, finding that the contexts in which single spaces occur in tokenized training data encourage models answer in lists or other formatted responses, overriding training signals to refuse unsafe requests. Our findings underscore the fragile state of current model alignment and promote the importance of developing more robust alignment methods.
Leon Lin, Hannah Brown, Kenji Kawaguchi, Michael Shieh
AAAI1
2013 A low-bandwidth camera sensor platform with applications in smart camera networks
abstract
Smart camera networks have recently emerged as a new class of sensor network infrastructure that is capable of supporting high-power in-network signal processing and enabling a wide range of applications. In this article, we provide an exposition of our efforts to build a low-bandwidth wireless camera network platform, called CITRIC, and its applications in smart camera networks. The platform integrates a camera, a microphone, a frequency-scalable (up to 624 MHz) CPU, 16 MB FLASH, and 64 MB RAM onto a single device. The device then connects with a standard sensor network mote to form a wireless camera mote. With reasonably low power consumption and extensive algorithmic libraries running on a decent operating system that is easy to program, CITRIC is ideal for research and applications in distributed image and video processing. Its capabilities of in-network image processing also reduce communication requirements, which has been high in other existing camera networks with centralized processing. Furthermore, the mote easily integrates with other low-bandwidth sensor networks via the IEEE 802.15.4 protocol. To justify the utility of CITRIC, we present several representative applications. In particular, concrete research results will be demonstrated in two areas, namely, distributed coverage hole identification and distributed object recognition.
Phoebus Chen, Kirak Hong, Nikhil Naikal, S. Shankar Sastry, J. D. Tygar, Posu Yan, Allen Y. Yang, Lung-Chung Chang, Leon Lin, Edgar J. Lobaton, Songhwai Oh, Parvez Ahammad
ACM Trans. Sens. Networks9
2009 Improving peer-to-peer search performance through intelligent social search
Stephen J. H. Yang, Jia Zhang 0001, Leon Lin, Jeffrey J. P. Tsai
Expert Syst. Appl.3
2006 Intersymbol and intercarrier interference canceller for multi-carrier modulation receivers
abstract
Multi-carrier modulation receivers are susceptible to performance degradation due to intersymbol and intercarrier interference. We present a scheme that modifies the conventional single-tap frequency-domain equalizer into a multi-tap equalizer that can be used to cancel both intersymbol and intercarrier interference while preserving the function of the channel equalization. We demonstrate a method to obtain the optimal coefficients that maximizes the signal-to-noise ratio for each tone. The proposed scheme can be incorporated straightforwardly into conventional multi-carrier modulation receivers, while offering flexibility to allow tradeoff between performance and computation cost.
Heng-Cheng Yeh, Leon Lin
ISCAS2