EDBT 2026 Demo / reviewers in the wild / expert
Jiacheng Liang
dblp:168/4584
· DBLP profile ↗
19ranked-venue papers
9as first author
16since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 8 · 2 first-author · 7 since 2021Applied, interdisciplinary, general and emerging computing · 6 · 5 first-author · 6 since 2021Security and privacy · 2 · 2 first-author · 2 since 2021Computer networks · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | AutoRAN: Automated Hijacking of Safety Reasoning in Large Reasoning ModelsabstractThis paper presents AutoRAN 1 , the first framework to automate the hijacking of internal safety reasoning in large reasoning models (LRMs).At its core, AutoRAN pioneers an execution simulation paradigm that leverages a weaker but less-aligned model to simulate execution reasoning for initial hijacking attempts and iteratively refine attacks by exploiting reasoning patterns leaked through the target LRM's refusals.This approach steers the target model to bypass its own safety guardrails and elaborate on harmful instructions.We evaluate AutoRAN against state-of-the-art LRMs, including gpt-o3/o4-mini and Gemini-2.5-Flash,across multiple benchmarks (AdvBench, Harm-Bench, and StrongReject).Results show that AutoRAN achieves approaching 100% success rate within one or a few turns, effectively neutralizing reasoning-based defenses even when evaluated by robustly aligned external models.This work reveals that the transparency of the reasoning process itself creates a critical and exploitable attack surface, highlighting the urgent need for new defenses that protect models' reasoning traces rather than merely their final outputs.The code for replicating Au-toRAN is available at: https://github.com/ JACKPURCELL/AutoRAN-public. Jiacheng Liang, Tanqiu Jiang, Yuhui Wang 0003, Rongyi Zhu, Fenglong Ma, Ting Wang 0006 |
ACL (1) | 1 |
| 2026 | ARES: Adaptive Red-Teaming and End-to-End Repair of Policy-Reward SystemabstractJiacheng Liang, Yao Ma, Tharindu Kumarage, Satyapriya Krishna, Rahul Gupta, Kai-Wei Chang, Aram Galstyan, Charith Peris. Proceedings of the 64th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2026. Jiacheng Liang, Tharindu Kumarage, Satyapriya Krishna, Rahul Gupta 0001, Kai-Wei Chang 0001, Aram Galstyan, Charith Peris |
ACL (1) | 1 |
| 2026 | GraphRAG Under FireabstractGraphRAG advances retrieval-augmented generation (RAG) by structuring external knowledge as multi-scale knowledge graphs, enabling language models to integrate both broad context and granular details in their generation. While GraphRAG has demonstrated success across domains, its security implications remain largely unexplored. To bridge this gap, this work examines GraphRAG's vulnerability to poisoning attacks, uncovering an intriguing security paradox: existing RAG poisoning attacks are less effective under GraphRAG than conventional RAG, due to GraphRAG's graph-based indexing and retrieval; yet, the same features also create new attack surfaces. We present GragPoison, a novel attack that exploits shared relations in the underlying knowledge graph to craft poisoning text capable of compromising multiple queries simultaneously. GragPoison employs three key strategies: (i) relation injection to introduce false knowledge, (ii) relation enhancement to amplify poisoning influence, and (iii) narrative generation to embed malicious content within coherent text. Empirical evaluation across diverse datasets and models shows that GragPoison substantially outperforms existing attacks in terms of effectiveness (up to 98% success rate) and scalability (using less than 68% poisoning text) on multiple variations of GraphRAG. We also explore potential defensive measures and their limitations, identifying promising directions for future research. Jiacheng Liang, Yuhui Wang 0003, Changjiang Li, Tanqiu Jiang, Rongyi Zhu, Neil Zhenqiang Gong, Ting Wang 0006 |
SP | 1 |
| 2025 | Data to Defense: The Role of Curation in Aligning Large Language Models Against Safety CompromiseabstractLarge language models (LLMs) are widely adapted for downstream applications through fine-tuning, a process named customization.However, recent studies have identified a vulnerability during this process, where malicious samples can compromise the robustness of LLMs and amplify harmful behaviors.To address this challenge, we propose an adaptive data curation approach allowing any text to be curated to enhance its effectiveness in counteracting harmful samples during customization.To avoid the need for additional defensive modules, we further introduce a comprehensive mitigation framework spanning the lifecycle of the customization process: before customization to immunize LLMs against future compromise attempts, during customization to neutralize risks, and after customization to restore compromised models.Experimental results demonstrate a significant reduction in compromising effects, achieving up to a 100% success rate in generating safe responses.By combining adaptive data curation with lifecycle-based mitigation strategies, this work represents a solid step forward in mitigating compromising risks and ensuring the secure adaptation of LLMs. Xiaoqun Liu, Jiacheng Liang, Luoxi Tang, Muchao Ye, Zhaohan Xi |
EMNLP | 2 |
| 2025 | RobustKV: Defending Large Language Models against Jailbreak Attacks via KV EvictionabstractJailbreak attacks circumvent LLMs' built-in safeguards by concealing harmful queries within adversarial prompts. While most existing defenses attempt to mitigate the effects of adversarial prompts, they often prove inadequate as adversarial prompts can take arbitrary, adaptive forms. This paper introduces RobustKV, a novel jailbreak defense that takes a fundamentally different approach by selectively removing critical tokens of harmful queries from key-value (KV) caches. Intuitively, for an adversarial prompt to be effective, its tokens must achieve sufficient `importance' (measured by attention scores), which consequently lowers the importance of tokens in the concealed harmful query. Therefore, by carefully evicting the KVs of low-ranked tokens, RobustKV minimizes the harmful query's presence in the KV cache, thus preventing the LLM from generating informative responses. Extensive evaluation using benchmark datasets and models demonstrates that RobustKV effectively counters state-of-the-art jailbreak attacks while maintaining the LLM's performance on benign queries. Notably, RobustKV creates an interesting effectiveness-evasiveness dilemma for the adversary, leading to its robustness against adaptive attacks.{(Warning: This paper contains potentially harmful content generated by LLMs.)} Tanqiu Jiang, Jiacheng Liang, Changjiang Li, Yuhui Wang 0003, Ting Wang 0006 |
ICLR | 3 |
| 2025 | Robust Adaptive Tracking Control for Aerial Transporting a Cable-Suspended Payload Using Backstepping Sliding Mode TechniquesabstractAerial transportation technology is the lifeline of air disaster rescue. In this article, a robust adaptive tracking control scheme using backstepping sliding mode techniques is proposed for a quadrotor-based aerial transportation system with a cable-suspended payload in disaster rescue, where the payload is ensured to be driven to predefined trajectories in the presence of strong coupling, uncertainties, and external disturbances. The quadrotor and the payload are modeled as a rigid body and a point mass, respectively, and the two coupling terms between the virtual input of the payload position loop and the payload attitude error as well as between the input force and the quadrotor attitude error are analyzed owing to the underactuated of the quadrotor-based transportation system. Then, adaptive backstepping sliding mode control strategies are designed for the position and swing dynamics of the payload to guarantee payload trajectory tracking, and an observer-based geometric attitude control method is presented for the quadrotor attitude dynamics to ensure the global attitude stability of the system, where prior information about disturbances is not required. The closed-loop stability of the whole system is strictly proven. Finally, real-world experiments are conducted to verify the feasibility and robustness of the proposed control scheme.Note to Practitioners—The motivation of this article is to investigate a robust and adaptive control tracking scheme for aerial transportation systems with a cable-suspended payload in disaster rescue. In most of the existing aerial transportation control schemes with a cable-suspended payload, the payload is driven to follow a desired trajectory while only considering the coupling effect between the aerial platform and the payload. However, in practical disaster rescue applications, the aerial transportation system is inevitably affected by strong coupling, uncertainties, and external disturbances. Meanwhile, to the authors’ best knowledge, there exist few studies that investigate payload following issues while considering strong coupling, uncertainties, and external disturbances simultaneously. Therefore, this article proposes a robust and adaptive tracking control scheme using backstepping sliding mode techniques for a quadrotor-based aerial transportation system with a cable-suspended payload to ensure the stable and accurate payload following control under strong coupling, uncertainties, and external disturbances, where prior information about disturbances is not required under the proposed scheme. The closed-loop stability of the whole system is strictly and mathematically analyzed as well as real-world experiments provide promising results. Moreover, the proposed scheme provides a more realistic setup for autonomous aerial transportation with cable-suspended supplies in disaster rescue. Jiacheng Liang, Yaonan Wang 0001, Hang Zhong, Hongwen Li, Hean Hua, Wei Wang 0025 |
IEEE Trans Autom. Sci. Eng. | 1 |
| 2025 | Prototype, Modeling, and Control of Aerial Robots With Physical Interaction: A ReviewabstractThis article aims to investigate the research achievements related to aerial robots with physical interaction. Various morphologies of aerial physical interaction (APhI) robot prototypes with fixed wing, flapping wing, single main rotor, conventional underactuated multirotor, fully actuated multirotor, even deformed multirotor, and multiple platforms are reviewed for different APhI tasks associated with momentary, loose, and strong interaction coupling. This review also covers APhI robot rigid dynamics and robot-environment coupled interaction dynamics modeling methods, interaction wrench measurement/estimation, decoupled and coupled control, active aerial interaction control, and task-constrained planning approaches. Finally, future development directions and prospects are initially anticipated for aerial robots with physical interaction.Note to Practitioners—Aerial physical interaction (APhI) has been a hot topic in the field of aerial robots in recent years, which is a reflection of the advanced capabilities of aerial robots. However, APhI robots face challenges such as difficulty in flight stability and weak adaptability to dynamic environments while exerting active influence on environments. Under this background, this review aims to offer a reference for researchers and practitioners engaged in the related field from the aspects of system design, modeling, control, and task-constrained planning, which hopes to help them apply APhI robots to polar scientific expeditions, complex environment sampling, infrastructure inspection and maintenance, and other application areas. Further, this review also highlights the design idea of rigid-soft integrated APhI robots from the perspective of design-mechanism-performance to enhance interaction stability and safety. Hang Zhong, Jiacheng Liang, Hui Zhang 0023, Jianxu Mao, Yaonan Wang 0001 |
IEEE Trans Autom. Sci. Eng. | 2 |
| 2024 | Model Extraction Attacks RevisitedabstractModel extraction (ME) attacks represent one major threat to Machine-Learning-as-a-Service (MLaaS) platforms by "stealing" the functionality of confidential machine-learning models through querying black-box APIs. Over seven years have passed since ME attacks were first conceptualized in the seminal work [75]. During this period, substantial advances have been made in both ME attacks and MLaaS platforms, raising the intriguing question: How has the vulnerability of MLaaS platforms to ME attacks been evolving? Jiacheng Liang, Ren Pang, Changjiang Li, Ting Wang 0006 |
AsiaCCS | 1 |
| 2024 | PASS: Patch Automatic Skip Scheme for Efficient On-Device Video PerceptionabstractReal-time video perception tasks are often challenging on resource-constrained edge devices due to the issues of accuracy drop and hardware overhead, where saving computations is the key to performance improvement. Existing methods either rely on domain-specific neural chips or priorly searched models, which require specialized optimization according to different task properties. These limitations motivate us to design a general and task-independent methodology, called Patch Automatic Skip Scheme (PASS), which supports diverse video perception settings by decoupling acceleration and tasks. The gist is to capture inter-frame correlations and skip redundant computations at patch level, where the patch is a non-overlapping square block in visual. PASS equips each convolution layer with a learnable gate to selectively determine which patches could be safely skipped without degrading model accuracy. Specifically, we are the first to construct a self-supervisory procedure for gate optimization, which learns to extract contrastive representations from frame sequences. The pre-trained gates can serve as plug-and-play modules to implement patch-skippable neural backbones, and automatically generate proper skip strategy to accelerate different video-based downstream tasks, e.g., outperforming state-of-the-art MobileHumanPose in 3D pose estimation and FairMOT in multiple object tracking, by up to 9.43 × and 12.19 × speedups, respectively, on NVIDIA Jetson Nano devices. Qihua Zhou, Song Guo 0001, Jiacheng Liang, Jingcai Guo, Zhenda Xu, Jingren Zhou 0001 |
IEEE Trans. Pattern Anal. Mach. Intell. | 4 |
| 2024 | Adaptive Force Tracking Impedance Control for Aerial Interaction in Uncertain Contact Environment Using Barrier FunctionabstractIn this article, an adaptive force tracking impedance control strategy is investigated for an aerial manipulator in physical interaction with uncertain contact environments. Based on the modified target impedance model, an adaptive impedance control method is proposed to accomplish aerial interaction in uncertain environments while maintaining a stable contact force, wherein the environment parameters of location and stiffness are estimated online to generate a reference position trajectory. Then, in order to ensure the tracking performance of the aerial manipulator, a robust pose tracking controller is designed, including a barrier function-based position controller and an adaptive attitude controller. Both proposed position and attitude controllers can ensure finite-time convergence of the state variable without the priori boundary information of disturbances. In particular, the position state variable can converge to a predefined neighborhood of zero from any initial state, and the control gain is not overestimated. The stability of the proposed strategy is analyzed via Lyapunov tools. Simulations and real-world experiments are conducted to illustrate the feasibility and performance of the proposed control strategy.Note to Practitioners—The motivation of this article is to investigate an adaptive force tracking impedance control strategy for aerial physical interaction with uncertain contact environments. In the existing impedance control schemes for aerial manipulators, the environment parameter of location or stiffness is often required to be utilized in controller design. However, in practical cases, the environmental parameters are not known precisely. Thus, this article presents an adaptive impedance method to automatically generate the reference position trajectory and achieve a stable contact force. Additionally, the tracking performance of the aerial manipulator is inevitably subject to uncertainties and disturbances. To ensure tracking convergence, traditional robust controllers generally involve high control gains than the known upper bounds of the disturbances. The main disadvantage of those controllers is that the control gain is often overestimated when the disturbance decreases. To address this issue, a barrier function-based position controller is proposed for the aerial manipulator, where the priori boundary information of disturbances is not needed and the control gain is adaptively adjusted according to the amplitude of disturbances. The stability and convergence of the proposed strategy are analyzed mathematically, and the experiments using an aerial manipulator provide promising results. Jiacheng Liang, Hang Zhong, Yaonan Wang 0001, Junhao Zeng, Jianxu Mao |
IEEE Trans Autom. Sci. Eng. | 1 |
| 2024 | Robust Variable Impedance Control for Aerial Compliant Interaction With Stability GuaranteeabstractThis article investigates a robust variable impedance control methodology for aerial manipulators to realize compliant and safe interaction tasks. Considering that the stability characteristics are generally overlooked in existing variable impedance controllers of the aerial manipulator, state-independent stability conditions are applied for time-varying impedance profiles to ensure the exponential stability of the desired variable impedance dynamics (DVID) as well as the boundedness of the state variables in the DVID. A command trajectory variable is introduced for converting the impedance control issue to a particular tracking issue, and then, a robust variable impedance controller based on the wrench estimator is designed to guarantee the exponential convergence of the translational states and impedance error of the aerial manipulator. The designed impedance controller is structurally simple and results in low implementation costs. Next, an improved attitude control approach with the command filter is developed for global flight attitude stability without any singularities or ambiguities, where the filter is introduced to avoid computing the derivative signals of the generalized force input. Finally, the effectiveness of the proposed control method is illustrated via numerical simulations and interaction experiments with different targets in real scenarios. Jiacheng Liang, Yaonan Wang 0001, Hang Zhong, Hongwen Li, Jianxu Mao, Wei Wang 0025 |
IEEE Trans. Ind. Informatics | 1 |
| 2023 | PASS: Patch Automatic Skip Scheme for Efficient Real-Time Video Perception on Edge DevicesabstractReal-time video perception tasks are often challenging over the resource-constrained edge devices due to the concerns of accuracy drop and hardware overhead, where saving computations is the key to performance improvement. Existing methods either rely on domain-specific neural chips or priorly searched models, which require specialized optimization according to different task properties. In this work, we propose a general and task-independent Patch Automatic Skip Scheme (PASS), a novel end-to-end learning pipeline to support diverse video perception settings by decoupling acceleration and tasks. The gist is to capture the temporal similarity across video frames and skip the redundant computations at patch level, where the patch is a non-overlapping square block in visual. PASS equips each convolution layer with a learnable gate to selectively determine which patches could be safely skipped without degrading model accuracy. As to each layer, a desired gate needs to make flexible skip decisions based on intermediate features without any annotations, which cannot be achieved by conventional supervised learning paradigm. To address this challenge, we are the first to construct a tough self-supervisory procedure for optimizing these gates, which learns to extract contrastive representation, i.e., distinguishing similarity and difference, from frame sequence. These high-capacity gates can serve as a plug-and-play module for convolutional neural network (CNN) backbones to implement patch-skippable architectures, and automatically generate proper skip strategy to accelerate different video-based downstream tasks, e.g., outperforming the state-of-the-art MobileHumanPose (MHP) in 3D pose estimation and FairMOT in multiple object tracking, by up to 9.43 times and 12.19 times speedups, respectively. By directly processing the raw data of frames, PASS can generalize to real-time video streams on commodity edge devices, e.g., NVIDIA Jetson Nano, with efficient performance in realistic deployment. Qihua Zhou, Song Guo 0001, Jiacheng Liang, Zhenda Xu, Jingren Zhou 0001 |
AAAI | 4 |
| 2023 | Adaptive Prescribed Performance Control of Unmanned Aerial Manipulator With DisturbancesabstractThis article presents the problem of autonomous control of an unmanned aerial manipulator (UAM) developed for operation with unknown disturbances, wherein the disturbances from the coupling effect between the UAM and the external environment need to be considered. Regarding the coupling force as a disturbance to the entire UAM system, an adaptive prescribed performance control (APPC) scheme utilizing the knowledge of prescribed performance is proposed to guarantee the transient and steady-state performance responses. Also, an adaptive law is designed to estimate the upper boundary parameters of the UAM system uncertainties and disturbances, wherein the restrictive constant boundary assumptions and the prior information of the upper bound are not required in the controller design. Furthermore, to enable safe manipulation in a realistic situation, an end-effector trajectory generation method is presented satisfying the joint angle limitation. For the validation of the proposed method, the simulation results of numerical simulation comparisons are shown. Moreover, experimental scenarios including stable flight and simulated co-work with humans in complex environments are designed to verify the proposed method.Note to Practitioners—This article is motivated by the problem of aerial manipulation under unknown disturbances, which may be caused by the wide movement of the manipulator and the sudden loading or unloading of an object. Existing approaches for aerial manipulation often require the assumption of a constant or slowly varying external disturbance. However, a priori bounded disturbance might impose a priori bound on the system state before obtaining closed-loop stability. In this article, the proposed controller with an adaptive law is designed to estimate the upper boundary parameters of the overall disturbances and ensure the predefined performance, so that the prior information of the upper bound of disturbances is not required. The performance of the proposed control strategy is demonstrated via numerical simulation comparisons and experiments, including stale flight and simulated co-work with humans in a complex environment. Jiacheng Liang, Yangning Wu, Zhiqiang Miao, Hui Zhang 0023, Yaonan Wang 0001 |
IEEE Trans Autom. Sci. Eng. | 1 |
| 2023 | Adaptive Sliding-Mode Disturbance Observer-Based Finite-Time Control for Unmanned Aerial Manipulator With Prescribed PerformanceabstractIn this article, an adaptive sliding-mode disturbance observer (ASMDO)-based finite-time control scheme with prescribed performance is proposed for an unmanned aerial manipulator (UAM) under uncertainties and external disturbances. First, to take into account the dynamic characteristics of the UAM, a dynamic model of the UAM with state-dependent uncertainties and external disturbances is introduced. Then, note that a priori bounded uncertainty may impose a priori constraint on the system state before obtaining closed-loop stability. To remove this assumption, an ASMDO with a nested adaptive structure is introduced to effectively estimate and compensate the external disturbances and state-dependent uncertainties in finite time without the information of the upper bound of the uncertainties and disturbances and their derivatives. Furthermore, based on the proposed ASMDO, the finite-time control scheme with the prescribed performance is presented to ensure finite-time convergence and implement the specified transient and steady-state performance. The Lyapunov tools are utilized to analyze the stability of the proposed controller. Finally, the correctness and performance of the proposed controller are illustrated through numerical simulation comparisons and outdoor experimental comparisons. Jiacheng Liang, Yangning Wu, Zhiqiang Miao, Hui Zhang 0023, Yaonan Wang 0001 |
IEEE Trans. Cybern. | 2 |
| 2022 | Revisiting Frequency Analysis against Encrypted Deduplication via Statistical DistributionabstractEncrypted deduplication addresses both security and storage efficiency in large-scale storage systems: it ensures that each plaintext is encrypted to a ciphertext by a symmetric key derived from the content of the plaintext, so as to allow deduplication on the ciphertexts derived from duplicate plaintexts. However, the deterministic nature of encrypted deduplication leaks the frequencies of plaintexts, thereby allowing adversaries to launch frequency analysis against encrypted deduplication and infer the ciphertext-plaintext pairs in storage. In this paper, we revisit the security vulnerability of encrypted deduplication due to frequency analysis, and show that encrypted deduplication can be even more vulnerable to the sophisticated frequency analysis attack that exploits the underlying storage workload characteristics. We propose the distribution-based attack, which builds on a statistical approach to model the relative frequency distributions of plaintexts and ciphertexts, and improves the inference precision (i.e., have high confidence on the correctness of inferred ciphertext-plaintext pairs) of the previous attack. We evaluate the new attack against real-world storage workloads and provide insights into its actual damage. Jingwei Li 0001, Guoli Wei, Jiacheng Liang, Yanjing Ren, Patrick P. C. Lee, Xiaosong Zhang 0001 |
INFOCOM | 3 |
| 2022 | Low-Complexity Prescribed Performance Control for Unmanned Aerial Manipulator Robot System Under Model Uncertainty and Unknown DisturbancesabstractThis article presents a trajectory tracking control method for the unmanned aerial manipulator robot system (UAMRS) under model uncertainty and unknown disturbances. More specifically, a low-complexity prescribed performance controller is proposed to effectively reduce the design complexity and achieve the prescribed transient and steady-state performance. First, the dynamics model of the UAMRS is analyzed and modeled, where the unmeasured internal interaction generated by the coupling effect and the random environmental disturbances are considered simultaneously. Then, utilizing the property of prescribed performance, the UAMRS with model uncertainty and external disturbances can guarantee preferable trajectory tracking responses, where the nonlinear disturbance observer is used to estimate and compensate uncertainties and external disturbances. Moreover, the proposed controller defined by simple expressions does not require accurate knowledge of the UAMRS, which is of low complexity and can effectively reduce the amount of calculation. The stability of the proposed controller is analyzed. Finally, the performances of the proposed scheme are demonstrated by the numerical simulation comparisons and real-world experiments, where a quadrotor with a 3-DOF onboard active manipulator is adopted in outdoor experimental validations. Jiacheng Liang, Ningbin Lai, Bingwei He, Zhiqiang Miao, Yaonan Wang 0001 |
IEEE Trans. Ind. Informatics | 1 |
| 2020 | Autonomous mobile robot path planning in unknown dynamic environments using neural dynamics
Jiacheng Liang, Yaonan Wang 0001, Qi Pan, Jianhao Tan, Jianxu Mao |
Soft Comput. | 2 |
| 2017 | Dynamic transition of scientific teams based on time slicingabstractBased on dynamic research perspectives of time slicing, this paper shows an endeavor on mining dynamic features of the scientific teams. Traditionally the static method of network structure analysis can successfully be used to analyze the distribution of network resource structure. But it cannot be used to explore the dynamic features of research groups, because of its lacks on the influence of some variables in research activities. These variables include researchers, research hotspots and research funds, etc. which are all in varying state due to the changing world. This paper proposes a new approach to analyze the dynamic characteristics of scientific teams, by using time slicing incorporated with traditional static method. KP(core members Keep-Rate) is used as an index of the dynamic transitions of scientific teams in two sequential time slices, and an algorithm is proposed to identify the successor team(s). Yuyao Li, Yong Tang 0001, Jiemin Chen, Jiacheng Liang |
CSCWD | 5 |
| 2015 | ONCAPS: An Ontology-Based Car Purchase Guiding System
Jianfeng Du, Jun Zhao 0003, Jiayi Cheng, Qingchao Su, Jiacheng Liang |
APWeb | 5 |