EDBT 2026 Demo / reviewers in the wild / expert
Shuai Zhao 0007
dblp:116/8682-7
· DBLP profile ↗
23ranked-venue papers
10as first author
23since 2021 · last 2026
0000-0001-5174-5182ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 20 · 8 first-author · 20 since 2021Security and privacy · 3 · 2 first-author · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | From Stimuli to Minds: Enhancing Psychological Reasoning in LLMs via Bilateral Reinforcement LearningabstractLarge Language Models show promise in emotion understanding, social reasoning, and empathy, yet struggle with psychologically grounded tasks requiring inference of implicit mental states in complex, socially and contextually ambiguous settings. These limitations stem from lacking theory-aligned supervision and difficulty capturing nuanced mental processes in real-world narratives. To bridge this gap, we leverage expert-labeled scenarios and propose a trajectory-aware reinforcement learning framework imitating expert psychological reasoning. By integrating real-world stimuli with structured reasoning guidance, our approach enables compact models to internalize social-cognitive principles, perform nuanced inference, and support continual self-improvement. Experiments across benchmarks show expert-level interpretive capability across psychological tasks. Yichao Feng, Haoran Luo 0001, Lang Feng 0007, Shuai Zhao 0007, Anh Tuan Luu |
AAAI | 4 |
| 2026 | DUP: Detection-guided Unlearning for Backdoor Purification in Language ModelsabstractAs backdoor attacks become more stealthy and robust, they reveal critical weaknesses in current defense strategies: detection methods often rely on coarse-grained feature statistics, and purification methods typically require full retraining or additional clean models. To address these challenges, we propose DUP (Detection-guided Unlearning for Purification), a unified framework that integrates backdoor detection with unlearning-based purification. The detector captures feature-level anomalies by jointly leveraging class-agnostic distances and inter-layer transitions. These deviations are integrated through a weighted scheme to identify poisoned inputs, enabling more fine-grained analysis. Based on the detection results, we purify the model through a parameter-efficient unlearning mechanism that avoids full retraining and does not require any external clean model. Specifically, we innovatively repurpose knowledge distillation to guide the student model toward increasing its output divergence from the teacher on detected poisoned samples, effectively forcing it to unlearn the backdoor behavior. Extensive experiments across diverse attack methods and language model architectures demonstrate that DUP achieves superior defense performance in detection accuracy and purification efficacy. Man Hu 0001, Yahui Ding, Yatao Yang 0001, Yanhao Jia, Shuai Zhao 0007 |
AAAI | 6 |
| 2026 | Artwork protection against unauthorized neural style transfer and aesthetic color distance metric
Zhongliang Guo 0001, Yifei Qian, Shuai Zhao 0007, Junhao Dong 0001, Ognjen Arandjelovic, Lei Fang 0001, Chun Pong Lau 0001 |
Pattern Recognit. | 3 |
| 2026 | Backdoor defense for large language models with weak-to-strong knowledge distillation
Zhongliang Guo 0001, Luwei Xiao, Yanhao Jia, Shuai Zhao 0007 |
Pattern Recognit. | 6 |
| 2026 | UniFLE: Uniform Fusion of Multiple LoRA Experts for Backdoor Defense in Large Language ModelsabstractLarge language models (LLMs), which serve as a bridge between pre-training and task-specific adaptation, achieve state-of-the-art performance across several downstream tasks through full-parameter fine-tuning (FPFT). However, with the continuous growth of model parameter scales, FPFT requires substantial computational resources, which limits its practicality. Consequently, there is a growing shift toward parameter-efficient fine-tuning (PEFT) methods that update only a limited subset of model parameters, markedly reducing resource consumption. Although this paradigm fosters accelerated research advancements, it also introduces security risks. Empirical studies demonstrate that if LLM weights are backdoored, the backdoors can still be activated even after fine-tuning leveraging PEFT algorithms. To address the aforementioned issue, in this paper, we introduce a novel Uniform Fusion of multiple LoRA Experts algorithm, named UniFLE, designed to defend against backdoor attacks. Specifically, the UniFLE algorithm pioneers the insertion of multiple LoRA experts into the MLP blocks to expand the updatable feature subspace during fine-tuning, and fuses all experts to decouple backdoor features. Additionally, to enhance the diversity of LoRA experts, we introduce a diversity regularization loss that constrains correlations between different experts and encourages them to learn more novel features. The theoretical analysis demonstrates that the UniFLE algorithm effectively decreases the mutual information between the model's intermediate representations and the backdoor representations. To validate the effectiveness of the UniFLE algorithm, we conduct experiments across four tasks, four state-of-the-art LLMs, and three backdoor attack methods. The results consistently demonstrate that our UniFLE algorithm effectively defends against backdoor attacks while preserving model performance. We aspire for our method to enhance model security and contribute to the advancement of the LLM community. Shuai Zhao 0007, Qika Lin, Yanhao Jia, Anh Tuan Luu |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2026 | Protecting Your Customized LLM Systems From Backdoored Instructions With Metacognitive Probing
Shuai Zhao 0007, Zhongliang Guo 0001, Xiaobao Wu, Yanhao Jia, Luwei Xiao, Anh Tuan Luu |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2025 | Uni-Retrieval: A Multi-Style Retrieval Framework for STEM's EducationabstractIn AI-facilitated teaching, leveraging various query styles to interpret abstract text descriptions is crucial for ensuring high-quality teaching. However, current retrieval models primarily focus on natural text-image retrieval, making them insufficiently tailored to educational scenarios due to the ambiguities in the retrieval process. In this paper, we propose a diverse expression retrieval task tailored to educational scenarios, supporting retrieval based on multiple query styles and expressions. We introduce the STEM Education Retrieval Dataset (SER), which contains over 24,000 query pairs of different styles, and the Uni-Retrieval, an efficient and style-diversified retrieval vision-language model based on prompt tuning. Uni-Retrieval extracts query style features as prototypes and builds a continuously updated Prompt Bank containing prompt tokens for diverse queries. This bank can updated during test time to represent domain-specific knowledge for different subject retrieval scenarios. Our framework demonstrates scalability and robustness by dynamically retrieving prompt tokens based on prototype similarity, effectively facilitating learning for unknown queries. Experimental results indicate that Uni-Retrieval outperforms existing retrieval models in most retrieval tasks. Yanhao Jia, Shuai Zhao 0007, Wenqi Fan |
ACL (1) | 6 |
| 2025 | AntiLeakBench: Preventing Data Contamination by Automatically Constructing Benchmarks with Updated Real-World KnowledgeabstractXiaobao Wu, Liangming Pan, Yuxi Xie, Ruiwen Zhou, Shuai Zhao, Yubo Ma, Mingzhe Du, Rui Mao, Anh Tuan Luu, William Yang Wang. Proceedings of the 63rd Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2025. Xiaobao Wu, Liangming Pan, Yuxi Xie, Ruiwen Zhou, Shuai Zhao 0007, Yubo Ma, Mingzhe Du, Rui Mao 0010, Anh Tuan Luu, William Yang Wang |
ACL (1) | 5 |
| 2025 | T2ICount: Enhancing Cross-modal Understanding for Zero-Shot CountingabstractZero-Shot object counting aims to count instances of arbitrary object categories specified by text descriptions. Existing methods typically rely on vision-language models like CLIP, but often exhibit limited sensitivity to text prompts. We present T21 Count, a diffusion-based framework that lever-ages rich prior knowledge and fine-grained visual understanding from pretrained diffusion models. While one-step demising ensures efficiency, it leads to weakened text sensitivity. To address this challenge, we propose a Hierarchical Semantic Correction Module that progressively refines text-image feature alignment, and a Representational Regional Coherence Loss that provides reliable supervision signals by leveraging the cross-attention maps extracted from the demising U-Net. Furthermore, we observe that current benchmarks mainly focus on majority objects in images, potentially masking models' text sensitivity. To address this, we contribute a challenging re-annotated subset of FSC147 for better evaluation of text-guided counting ability. Extensive experiments demonstrate that our method achieves superior performance across different benchmarks. Code is available at https://github.com/chal5yq/T2lCount. Yifei Qian, Zhongliang Guo 0001, Bowen Deng 0006, Chun Tong Lei, Shuai Zhao 0007, Chun Pong Lau 0001, Xiaopeng Hong, Michael P. Pound |
CVPR | 5 |
| 2025 | Aspect-Based Summarization with Self-Aspect Retrieval Enhanced GenerationabstractAspect-based summarization aims to generate summaries tailored to specific aspects, addressing the resource constraints and limited generalizability of traditional summarization approaches. Recently, large language models have shown promise in this task without the need for training. However, they rely excessively on prompt engineering and face token limits and hallucination challenges, especially with in-context learning. To address these challenges, in this paper, we propose a novel framework for aspect-based summarization: Self-Aspect Retrieval Enhanced Summary Generation. Rather than relying solely on in-context learning, given an aspect, we employ an embedding-driven retrieval mechanism to identify its relevant text segments. This approach extracts the pertinent content while avoiding unnecessary details, thereby mitigating the challenge of token limits. Moreover, our framework optimizes token usage by deleting unrelated parts of the text and ensuring that the model generates output strictly based on the given aspect. With extensive experiments on benchmark datasets, we demonstrate that our framework not only achieves superior performance but also effectively mitigates the token limitation problem. Yichao Feng, Shuai Zhao 0007, Yueqiu Li, Luwei Xiao, Xiaobao Wu, Anh Tuan Luu |
IJCNN | 2 |
| 2025 | Enhancing Multimodal Entity Linking with Jaccard Distance-based Conditional Contrastive Learning and Contextual Visual AugmentationabstractCong-Duy T Nguyen, Xiaobao Wu, Thong Thanh Nguyen, Shuai Zhao, Khoi M. Le, Nguyen Viet Anh, Feng Yichao, Anh Tuan Luu. Proceedings of the 2025 Conference of the Nations of the Americas Chapter of the Association for Computational Linguistics: Human Language Technologies (Volume 1: Long Papers). 2025. Cong-Duy Nguyen, Xiaobao Wu, Thong Thanh Nguyen, Shuai Zhao 0007, Khoi M. Le, Yichao Feng, Anh Tuan Luu |
NAACL (Long Papers) | 4 |
| 2025 | Clean-label backdoor attack and defense: An examination of language model vulnerability
Shuai Zhao 0007, Luwei Xiao, Jinming Wen, Anh Tuan Luu |
Expert Syst. Appl. | 1 |
| 2025 | Exploring Cognitive and Aesthetic Causality for Multimodal Aspect-Based Sentiment AnalysisabstractMultimodal aspect-based sentiment classification (MASC) is an emerging task due to an increase in user-generated multimodal content on social platforms, aimed at predicting sentiment polarity toward specific aspect targets (i.e., entities or attributes explicitly mentioned in text-image pairs). Despite extensive efforts and significant achievements in existing MASC, substantial gaps remain in understanding fine-grained visual content and the cognitive rationales derived from semantic content and impressions (cognitive interpretations of emotions evoked by image content). In this study, we present Chimera: acognitive and aesthetic sentiment causality understanding framework to derive fine-grained holistic features of aspects and infer the fundamental drivers of sentiment expression from both semantic perspectives and affective-cognitive resonance (the synergistic effect between emotional responses and cognitive interpretations). The framework aligns visual patches with words, extracts coarse and fine-grained visual features, translates them into textual descriptions, and uses LLM-generated sentimental causes and impressions to boost sensitivity to affective cues. Experiments on MASC datasets show the model's effectiveness and greater flexibility compared to LLMs like GPT-4o. We have publicly released the complete implementation and dataset athttps://github.com/Xillv/Chimera Luwei Xiao, Rui Mao 0010, Shuai Zhao 0007, Qika Lin, Yanhao Jia, Liang He 0001, Erik Cambria |
IEEE Trans. Affect. Comput. | 3 |
| 2025 | A Gray-Box Attack Against Latent Diffusion Model-Based Image Editing by Posterior CollapseabstractRecent advancements in Latent Diffusion Models (LDMs) have revolutionized image synthesis and manipulation, raising significant concerns about data misappropriation and intellectual property infringement. While adversarial attacks have been extensively explored as a protective measure against such misuse of generative AI, current approaches are severely limited by their heavy reliance on model-specific knowledge and substantial computational costs. Drawing inspiration from the posterior collapse phenomenon observed in VAE training, we propose the Posterior Collapse Attack (PCA), a novel framework for protecting images from unauthorized manipulation. Through comprehensive theoretical analysis and empirical validation, we identify two distinct collapse phenomena during VAE inference: diffusion collapse and concentration collapse. Based on this discovery, we design a unified loss function that can flexibly achieve both types of collapse through parameter adjustment, each corresponding to different protection objectives in preventing image manipulation. Our method significantly reduces dependence on model-specific knowledge by requiring access to only the VAE encoder, which constitutes less than 4% of LDM parameters. Notably, PCA achieves prompt-invariant protection by operating on the VAE encoder before text conditioning occurs, eliminating the need for empty prompt optimization required by existing methods. This minimal requirement enables PCA to maintain adequate transferability across various VAE-based LDM architectures while effectively preventing unauthorized image editing. Extensive experiments show PCA outperforms existing techniques in protection effectiveness, computational efficiency (runtime and VRAM), and generalization across VAE-based LDM variants. Our code is available at https://github.com/ZhongliangGuo/PosteriorCollapseAttack. Zhongliang Guo 0001, Chun Tong Lei, Lei Fang 0001, Shuai Zhao 0007, Yifei Qian, Zeyu Wang 0010, Cunjian Chen, Ognjen Arandjelovic, Chun Pong Lau 0001 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2024 | Universal Vulnerabilities in Large Language Models: Backdoor Attacks for In-context LearningabstractIn-context learning, a paradigm bridging the gap between pre-training and fine-tuning, has demonstrated high efficacy in several NLP tasks, especially in few-shot settings. Despite being widely applied, in-context learning is vulnerable to malicious attacks. In this work, we raise security concerns regarding this paradigm. Our studies demonstrate that an attacker can manipulate the behavior of large language models by poisoning the demonstration context, without the need for fine-tuning the model. Specifically, we design a new backdoor attack method, named ICLAttack, to target large language models based on in-context learning. Our method encompasses two types of attacks: poisoning demonstration examples and poisoning demonstration prompts, which can make models behave in alignment with predefined intentions. ICLAttack does not require additional fine-tuning to implant a backdoor, thus preserving the model’s generality. Furthermore, the poisoned examples are correctly labeled, enhancing the natural stealth of our attack method. Extensive experimental results across several language models, ranging in size from 1.3B to 180B parameters, demonstrate the effectiveness of our attack method, exemplified by a high average attack success rate of 95.0% across the three datasets on OPT models. Shuai Zhao 0007, Meihuizi Jia, Anh Tuan Luu, Fengjun Pan, Jinming Wen |
EMNLP | 1 |
| 2024 | A simple and efficient filter feature selection method via document-term matrix unitization
Qing Li 0042, Shuai Zhao 0007, Tengjiao He, Jinming Wen |
Pattern Recognit. Lett. | 2 |
| 2024 | Exploring Clean Label Backdoor Attacks and Defense in Language ModelsabstractDespite being widely applied, pre-trained language models have been proven vulnerable to backdoor attacks. Backdoor attacks are designed to introduce targeted vulnerabilities into models by poisoning a subset of training samples through trigger injection and label modification. Traditional textual backdoor attacks suffer several flaws: the triggers lead to abnormal natural language expressions, and poisoned sample labels are mistakenly labeled. These flaws reduce the stealthiness of the attack and can be easily detected by defense models. In this study, we introduce Cbat, a novel and efficient method to perform clean-label backdoor attack with text style, which does not require external trigger, and the poisoned samples are correctly labeled. Specifically, we develop a sentence rewriting model by leveraging the powerful few-shot learning capability of prompt tuning to generate clean label poisoned samples. Cbat then injects text style as an abstract trigger into the victim model through poisoned samples. We also introduce an algorithm for defending against backdoor attacks, named CbatD, which effectively erases the poisoned samples by locating the lowest training loss and calculating feature relevance. The experiments on text classification tasks demonstrate that our Cbat and CbatD show overall competitive performance in textual backdoor attack and defense. It is noteworthy that Cbat attained leading results in the clean-label backdoor attack benchmark without triggers. Shuai Zhao 0007, Anh Tuan Luu, Jie Fu 0001, Jinming Wen, Weiqi Luo 0002 |
IEEE ACM Trans. Audio Speech Lang. Process. | 1 |
| 2023 | Prompt as Triggers for Backdoor Attack: Examining the Vulnerability in Language ModelsabstractThe prompt-based learning paradigm, which bridges the gap between pre-training and finetuning, achieves state-of-the-art performance on several NLP tasks, particularly in few-shot settings.Despite being widely applied, promptbased learning is vulnerable to backdoor attacks.Textual backdoor attacks are designed to introduce targeted vulnerabilities into models by poisoning a subset of training samples through trigger injection and label modification.However, they suffer from flaws such as abnormal natural language expressions resulting from the trigger and incorrect labeling of poisoned samples.In this study, we propose ProAttack, a novel and efficient method for performing clean-label backdoor attacks based on the prompt, which uses the prompt itself as a trigger.Our method does not require external triggers and ensures correct labeling of poisoned samples, improving the stealthy nature of the backdoor attack.With extensive experiments on rich-resource and few-shot text classification tasks, we empirically validate ProAttack's competitive performance in textual backdoor attacks.Notably, in the rich-resource setting, ProAttack achieves state-of-the-art attack success rates in the clean-label backdoor attack benchmark without external triggers 1 . Shuai Zhao 0007, Jinming Wen, Anh Tuan Luu, Jie Fu 0001 |
EMNLP | 1 |
| 2023 | Sparse summary generation
Shuai Zhao 0007, Tengjiao He, Jinming Wen |
Appl. Intell. | 1 |
| 2023 | Logistic Regression Matching Pursuit algorithm for text classification
Qing Li 0042, Shuai Zhao 0007, Shancheng Zhao, Jinming Wen |
Knowl. Based Syst. | 2 |
| 2023 | A Step-by-Step Gradient Penalty with Similarity Calculation for Text Summary Generation
Shuai Zhao 0007, Qing Li 0042, Tengjiao He, Jinming Wen |
Neural Process. Lett. | 1 |
| 2023 | From Softmax to Nucleusmax: A Novel Sparse Language Model for Chinese Radiology Report SummarizationabstractThe Chinese radiology report summarization is a crucial component in smart healthcare that employs language models to summarize key findings in radiology reports and communicate these findings to physicians. However, most language models for radiology report summarization utilize a softmax transformation in their output layer, leading to dense alignments and strictly positive output probabilities. This density is inefficient, reducing model interpretability and giving probability mass to many unrealistic outputs. To tackle this issue, we propose a novel approach named nucleusmax. Nucleusmax is able to mitigate dense outputs and improve model interpretability by truncating the unreliable tail of the probability distribution. In addition, we incorporate nucleusmax with a copy mechanism, a useful technique to avoid professional errors in the generated diagnostic opinions. To further promote the research of radiology report summarization, we also have created a Chinese radiology report summarization dataset, which is freely available. Experimental results showed via both automatic and human evaluation that the proposed approach substantially improves the sparsity and overall quality of outputs over competitive softmax models, producing radiology summaries that approach the quality of those authored by physicians. In general, our work demonstrates the feasibility and prospect of the language model to the domain of radiology and smart healthcare. Shuai Zhao 0007, Qing Li 0042, Yuer Yang, Jinming Wen, Weiqi Luo 0002 |
ACM Trans. Asian Low Resour. Lang. Inf. Process. | 1 |
| 2022 | AP-BERT: enhanced pre-trained model through average pooling
Shuai Zhao 0007, Man Hu 0001, Wen Chang, Fucheng You |
Appl. Intell. | 1 |