Jianing Zhu

dblp:129/6807 · DBLP profile ↗
← Back
18ranked-venue papers
6as first author
15since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 13 · 6 first-author · 13 since 2021Systems, architecture and hardware · 3 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 since 2021
YearPublicationVenuePosition
2026 Traditional, subscription, or data compensation: An economic analysis of optimal privacy protection models on ad-supported platforms
Jianing Zhu, Haiyang Feng
Decis. Support Syst.2
2026 Slack Federated Adversarial Training
abstract
Security and privacy concerns in real-world applications have led to the development of adversarially robust federated models. Previous works mainly target overcoming the adaptability constraints regarding communication and computation costs. However, the straightforward combination of adversarial training and federated learning might lead to undesired robust accuracy degradation emerging at later training stages. We reveal that the attribution behind this phenomenon is that the generated adversarial data could exacerbate the data heterogeneity among local clients, making the wrapped federated learning perform poorly. To deal with this problem, we introduce an $\alpha$α-slack mechanism to relax the original learning objective of federated adversarial training, and propose a novel framework called Slack Federated Adversarial Training (SFAT) to combat the intensified heterogeneity. By assigning the client-wise slack during aggregation, SFAT realizes a weighted aggregation that alleviates the optimization bias induced by the local adversarial generation. We further extend to a more general setting, permitting both clients trained by standard/adversarial training in a unified framework, and propose SFAT* with a hierarchical aggregation schema for this scenario. Theoretically, we analyze the convergence of our method to properly relax the learning objective. Experimentally, we verify the rationality and effectiveness of our methods on various benchmarked and real-world datasets with different adversarial training and federated optimization methods.
Jianing Zhu, Bo Han 0003, Jiangchao Yao, Quanming Yao, Tongliang Liu, Jianliang Xu
IEEE Trans. Pattern Anal. Mach. Intell.1
2025 Towards Effective Evaluations and Comparisons for LLM Unlearning Methods
abstract
The imperative to eliminate undesirable data memorization underscores the significance of machine unlearning for large language models (LLMs). Recent research has introduced a series of promising unlearning methods, notably boosting the practical significance of the field. Nevertheless, adopting a proper evaluation framework to reflect the true unlearning efficacy is also essential yet has not received adequate attention. This paper seeks to improve the evaluation of LLM unlearning by addressing two key challenges---a) the robustness of evaluation metrics and b) the trade-offs between competing goals. The first challenge stems from findings that current metrics are susceptible to various red teaming scenarios. It indicates that they may not reflect the true extent of knowledge retained by LLMs but rather tend to mirror superficial model behaviors, thus prone to attacks. We address this issue by devising and assessing a series of candidate metrics, selecting the most robust ones under various types of attacks. The second challenge arises from the conflicting goals of eliminating unwanted knowledge while retaining those of others. This trade-off between unlearning and retention often fails to conform the Pareto frontier, rendering it subtle to compare the efficacy between methods that excel only in either unlearning or retention. We handle this issue by proposing a calibration method that can restore the original performance on non-targeted data after unlearning, thereby allowing us to focus exclusively on assessing the strength of unlearning. Our evaluation framework notably enhances the effectiveness when assessing and comparing various LLM unlearning methods, further allowing us to benchmark existing works, identify their proper hyper-parameters, and explore new tricks to enhance their practical efficacy.
Bo Han 0003, Puning Yang, Jianing Zhu, Tongliang Liu, Masashi Sugiyama
ICLR4
2024 Self-Calibrated Tuning of Vision-Language Models for Out-of-Distribution Detection
abstract
Out-of-distribution (OOD) detection is crucial for deploying reliable machine learning models in open-world applications. Recent advances in CLIP-based OOD detection have shown promising results via regularizing prompt tuning with OOD features extracted from ID data. However, the irrelevant context mined from ID data can be spurious due to the inaccurate foreground-background decomposition, thus limiting the OOD detection performance. In this work, we propose a novel framework, namely, \textit{Self-Calibrated Tuning (SCT)}, to mitigate this problem for effective OOD detection with only the given few-shot ID data. Specifically, SCT introduces modulating factors respectively on the two components of the original learning objective. It adaptively directs the optimization process between the two tasks during training on data with different prediction uncertainty to calibrate the influence of OOD regularization, which is compatible with many prompt tuning based OOD detection methods. Extensive experiments and analyses have been conducted to characterize and demonstrate the effectiveness of the proposed SCT. The code is publicly available at: https://github.com/tmlr-group/SCT.
Geng Yu, Jianing Zhu, Jiangchao Yao, Bo Han 0003
NeurIPS2
2024 What If the Input is Expanded in OOD Detection?
abstract
Out-of-distribution (OOD) detection aims to identify OOD inputs from unknown classes, which is important for the reliable deployment of machine learning models in the open world. Various scoring functions are proposed to distinguish it from in-distribution (ID) data. However, existing methods generally focus on excavating the discriminative information from a single input, which implicitly limits its representation dimension. In this work, we introduce a novel perspective, i.e., employing different common corruptions on the input space, to expand that. We reveal an interesting phenomenon termed *confidence mutation*, where the confidence of OOD data can decrease significantly under the corruptions, while the ID data shows a higher confidence expectation considering the resistance of semantic features. Based on that, we formalize a new scoring method, namely, *Confidence aVerage* (CoVer), which can capture the dynamic differences by simply averaging the scores obtained from different corrupted inputs and the original ones, making the OOD and ID distributions more separable in detection tasks. Extensive experiments and analyses have been conducted to understand and verify the effectiveness of CoVer.
Boxuan Zhang 0001, Jianing Zhu, Zengmao Wang, Tongliang Liu, Bo Du 0001, Bo Han 0003
NeurIPS2
2024 Can Language Models Perform Robust Reasoning in Chain-of-thought Prompting with Noisy Rationales?
abstract
This paper investigates an under-explored challenge in large language models (LLMs): chain-of-thought prompting with noisy rationales, which include irrelevant or inaccurate reasoning thoughts within examples used for in-context learning. We construct NoRa dataset that is tailored to evaluate the robustness of reasoning in the presence of noisy rationales. Our findings on NoRa dataset reveal a prevalent vulnerability to such noise among current LLMs, with existing robust methods like self-correction and self-consistency showing limited efficacy. Notably, compared to prompting with clean rationales, base LLM drops by 1.4%-19.8% in accuracy with irrelevant thoughts and more drastically by 2.2%-40.4% with inaccurate thoughts. Addressing this challenge necessitates external supervision that should be accessible in practice. Here, we propose the method of contrastive denoising with noisy chain-of-thought (CD-CoT). It enhances LLMs' denoising-reasoning capabilities by contrasting noisy rationales with only one clean rationale, which can be the minimal requirement for denoising-purpose prompting. This method follows a principle of exploration and exploitation: (1) rephrasing and selecting rationales in the input space to achieve explicit denoising and (2) exploring diverse reasoning paths and voting on answers in the output space. Empirically, CD-CoT demonstrates an average improvement of 17.8% in accuracy over the base model and shows significantly stronger denoising capabilities than baseline methods. The source code is publicly available at: https://github.com/tmlr-group/NoisyRationales.
Zhanke Zhou, Rong Tao, Jianing Zhu, Yiwen Luo, Zengmao Wang, Bo Han 0003
NeurIPS3
2023 Combating Exacerbated Heterogeneity for Robust Models in Federated Learning
Jianing Zhu, Jiangchao Yao, Tongliang Liu, Quanming Yao, Jianliang Xu, Bo Han 0003
ICLR1
2023 Exploring Model Dynamics for Accumulative Poisoning Discovery
abstract
Adversarial poisoning attacks pose huge threats to various machine learning applications. Especially, the recent accumulative poisoning attacks show that it is possible to achieve irreparable harm on models via a sequence of imperceptible attacks followed by a trigger batch. Due to the limited data-level discrepancy in real-time data streaming, current defensive methods are indiscriminate in handling the poison and clean samples. In this paper, we dive into the perspective of model dynamics and propose a novel information measure, namely, Memorization Discrepancy, to explore the defense via the model-level information. By implicitly transferring the changes in the data manipulation to that in the model outputs, Memorization Discrepancy can discover the imperceptible poison samples based on their distinct dynamics from the clean samples. We thoroughly explore its properties and propose Discrepancy-aware Sample Correction (DSC) to defend against accumulative poisoning attacks. Extensive experiments comprehensively characterized Memorization Discrepancy and verified its effectiveness. The code is publicly available at: https://github.com/tmlr-group/Memorization-Discrepancy.
Jianing Zhu, Xiawei Guo, Jiangchao Yao, Tongliang Liu, Liang Wang 0001, Bo Han 0003
ICML1
2023 Unleashing Mask: Explore the Intrinsic Out-of-Distribution Detection Capability
abstract
Out-of-distribution (OOD) detection is an indispensable aspect of secure AI when deploying machine learning models in real-world applications. Previous paradigms either explore better scoring functions or utilize the knowledge of outliers to equip the models with the ability of OOD detection. However, few of them pay attention to the intrinsic OOD detection capability of the given model. In this work, we generally discover the existence of an intermediate stage of a model trained on in-distribution (ID) data having higher OOD detection performance than that of its final stage across different settings, and further identify one critical data-level attribution to be learning with the atypical samples. Based on such insights, we propose a novel method, Unleashing Mask, which aims to restore the OOD discriminative capabilities of the well-trained model with ID data. Our method utilizes a mask to figure out the memorized atypical samples, and then finetune the model or prune it with the introduced mask to forget them. Extensive experiments and analysis demonstrate the effectiveness of our method. The code is available at: https://github.com/tmlr-group/Unleashing-Mask.
Jianing Zhu, Hengzhuang Li, Jiangchao Yao, Tongliang Liu, Jianliang Xu, Bo Han 0003
ICML1
2023 Diversified Outlier Exposure for Out-of-Distribution Detection via Informative Extrapolation
abstract
Out-of-distribution (OOD) detection is important for deploying reliable machine learning models on real-world applications. Recent advances in outlier exposure have shown promising results on OOD detection via fine-tuning model with informatively sampled auxiliary outliers. However, previous methods assume that the collected outliers can be sufficiently large and representative to cover the boundary between ID and OOD data, which might be impractical and challenging. In this work, we propose a novel framework, namely, Diversified Outlier Exposure (DivOE), for effective OOD detection via informative extrapolation based on the given auxiliary outliers. Specifically, DivOE introduces a new learning objective, which diversifies the auxiliary distribution by explicitly synthesizing more informative outliers for extrapolation during training. It leverages a multi-step optimization method to generate novel outliers beyond the original ones, which is compatible with many variants of outlier exposure. Extensive experiments and analyses have been conducted to characterize and demonstrate the effectiveness of the proposed DivOE. The code is publicly available at: https://github.com/tmlr-group/DivOE.
Jianing Zhu, Jiangchao Yao, Tongliang Liu, Gang Niu 0001, Masashi Sugiyama, Bo Han 0003
NeurIPS1
2022 Reliable Adversarial Distillation with Unreliable Teachers
Jianing Zhu, Jiangchao Yao, Bo Han 0003, Jingfeng Zhang, Tongliang Liu, Gang Niu 0001, Jingren Zhou 0001, Jianliang Xu, Hongxia Yang
ICLR1
2022 Adversarial Training with Complementary Labels: On the Benefit of Gradually Informative Attacks
abstract
Adversarial training (AT) with imperfect supervision is significant but receives limited attention. To push AT towards more practical scenarios, we explore a brand new yet challenging setting, i.e., AT with complementary labels (CLs), which specify a class that a data sample does not belong to. However, the direct combination of AT with existing methods for CLs results in consistent failure, but not on a simple baseline of two-stage training. In this paper, we further explore the phenomenon and identify the underlying challenges of AT with CLs as intractable adversarial optimization and low-quality adversarial examples. To address the above problems, we propose a new learning strategy using gradually informative attacks, which consists of two critical components: 1) Warm-up Attack (Warm-up) gently raises the adversarial perturbation budgets to ease the adversarial optimization with CLs; 2) Pseudo-Label Attack (PLA) incorporates the progressively informative model predictions into a corrected complementary loss. Extensive experiments are conducted to demonstrate the effectiveness of our method on a range of benchmarked datasets. The code is publicly available at: https://github.com/RoyalSkye/ATCL.
Jianan Zhou 0002, Jianing Zhu, Jingfeng Zhang, Tongliang Liu, Gang Niu 0001, Bo Han 0003, Masashi Sugiyama
NeurIPS2
2022 BAM: Block attention mechanism for OCT image classification
abstract
Abstract Diabetic retinopathy attracts considerable research interest due to the number of diabetic patients increasing rapidly in recent years. Diabetic retinopathy is a common symptom of retinopathy, which damages the patient's eyesight and even causes the patient to lose sight. The authors propose a novel attention mechanism named block attention mechanism to actively explore the role of attention mechanisms in recognizing retinopathy features. Specifically, the block attention mechanism contributions are as follows: (1) The relationship between the blocks in the entire feature map is explored, and the corresponding coefficients are assigned to different blocks to highlight the importance of blocks. (2) Furthermore, the relationship between the edge elements of the feature map and the edge elements is explored, and corresponding coefficients are assigned to the elements at different positions on the feature map to highlight the importance of the elements in the feature map. Experimental results show that the proposed framework outperforms the existing popular attention‐based baselines on two public retina datasets, OCT2017 and SD‐OCT, achieving a 99.64% and 96.54% accuracy rate, respectively.
Maidina Nabijiang, Xinjuan Wan, Shengsong Huang, Bixia Wei, Jianing Zhu
IET Image Process.6
2021 Geometry-aware Instance-reweighted Adversarial Training
Jingfeng Zhang, Jianing Zhu, Gang Niu 0001, Bo Han 0003, Masashi Sugiyama, Mohan Kankanhalli
ICLR2
2021 Component Based and Machine Learning Aided Optimal Filter Design for Full-Bridge Current Doubler Rectifier
abstract
Full-bridge current doubler rectifier topology is used to restrict the ripple of output current and quicken the dynamic response. However, mass and power loss of filter composed of passive components are large. To optimize the output filter parameters, this paper adopts machine learning (ML) methods to train a support vector machine (SVM) model and an artificial neural network (ANN) model using data samples collected from simulation. SVM is used to judge the feasibility of filter design parameters, and the trained ANN serves as a dedicated surrogate model mapping from the design variables to the two optimization objectives (mass and power loss). After the ML aided filter optimization, the filter prototype based on the optimal design point is manufactured and tested on an experiment platform for the method validation.
Guihua Liu, Yanbo Chen 0005, Yuan Gao 0028, Jianing Zhu, Bo-Xin Wang, Tao Yang 0020
IECON4
2020 Detection Features as Attention (Defat): A Keypoint-Free Approach to Amur Tiger Re-Identification
abstract
Automatically identifying animals in camera-trap images has attracted increasing attention due to its valuable potential in wildlife conservation. A typical pipeline of existing methods includes separated animal detection and re-identification modules, and state-of-the-art re-identification methods either use annotated keypoints of animals to extract robust features, or employ extra branches to learn multiple features. In this paper, in contrast, we propose a keypoint-free approach to Amur tiger re-identification by exploiting the feature maps extracted by the detection module to help the re-identification module learn more effective features. We devise a detection-features-as-attention (DeFAt) module, which generates an additive mask for the input image based on the detection feature maps. We experimentally show that using the masked image the re-identification module lays more attention on the tiger region in the image, while the distraction by the messy background is removed to some extent. Our evaluation results prove that the proposed DeFAt module can effectively improve the Amur tiger re-identification accuracy when key-point annotations are not available.
Xinhua Cheng, Jianing Zhu, Qijun Zhao
ICIP2
2020 Synchronous Control Method of Three-phase Inverter Under Unbalanced Conditions Using the Energy Operator
abstract
Unbalanced three-phase voltages, harmonics and DC offset to the grid voltage will affect the speed and accuracy of a grid-connected inverter when estimating the frequency and phase angle of the grid voltage. Existing synchronization methods were difficult in accurately estimating the phase angle of the three-phase voltages. To solve these problems, this paper proposes a synchronous control method for three-phase grid-connected inverters using the energy operator. First, the cascade delay signal cancellation algorithm is used to eliminate harmonics and DC offset of the grid voltage, and the grid voltage is unitized to eliminate the adverse effects of unbalanced amplitudes. After that the energy operator is applied to obtain the frequency and the phase angle of the thee-phase input voltages. Therefore, the inverter and the grid voltage can be accurately synchronized even under unbalanced grid voltage conditions with harmonic distortion and DC offset. Finally, simulation results are used to verify the effectiveness of the synchronous control method proposed in this paper.
Guihua Liu, Wenxiu Wang, Jianing Zhu, Pat Wheeler
IECON3
2020 A Novel FLL for Single-Phase Grid-Connected PV Inverter Under Weak Grid
abstract
The weak grid with high line impedance and low short-circuit capacity leads to a large number of background harmonics and fluctuation of the grid voltage, and it is difficult for the inverter to synchronize with the weak grid. In order to overcome these problems, a novel fast and accurate frequency-locked loop(FLL) method is proposed. Firstly, an improved quadrature signal generator(QSG) is utilized to effectively eliminate the impact of the DC offset on the accuracy of frequency and phase detection. Secondly, low-pass filters(LPF) with specific harmonic filtering capabilities are used so that the system has good dynamic response speed and anti-interference ability. Finally, the grid frequency is calculated by the Teager energy operator(TEO) algorithm without any parameter adjustment, and use Park transform to obtain grid phase information. It can be known from the modeling that the FLL system is a type I system with an excellent dynamic response speed and stability margin. The simulation results verify the effectiveness of the proposed method when the grid voltage fluctuates or distorted.
Guihua Liu, Jianing Zhu, Wenxiu Wang
IECON2