Haojie Hao

dblp:175/7351 · DBLP profile ↗
← Back
5ranked-venue papers
1as first author
4since 2021 · last 2026
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 4 · 1 first-author · 4 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 1 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Artificial intelligence
4 papers
Generative modeling · 36% Efficient and distributed learning · 36% Trustworthy machine learning · 15%
Network and information security
3 papers
Security and privacy of machine learning · 100%

Topics — the 13 heaviest of 14, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Machine learning › Generative modeling
diffusion model
1.722025
BinaryDM: Accurate Weight Binarization for Efficient Diffusion Models · ICLR 2025
Harnessing Global-Local Collaborative Adversarial Perturbation for Anti-Customization · CVPR 2025
Security and privacy of machine learning › adversarial attack
jailbreak attack
1.012026
Activation Manipulation Attack: Penetrating and Harmful Jailbreak Attack Against Large Vision-Language Models · AAAI 2026
Security and privacy of machine learning › adversarial attack › multimodal adversarial attack
vision-language model attack
1.012026
Activation Manipulation Attack: Penetrating and Harmful Jailbreak Attack Against Large Vision-Language Models · AAAI 2026
Machine learning › Generative modeling › diffusion model
efficient diffusion model
0.912025
BinaryDM: Accurate Weight Binarization for Efficient Diffusion Models · ICLR 2025
Machine learning › Efficient and distributed learning
model compression
0.912025
BinaryDM: Accurate Weight Binarization for Efficient Diffusion Models · ICLR 2025
Machine learning › Efficient and distributed learning › model compression
quantization
0.912025
BinaryDM: Accurate Weight Binarization for Efficient Diffusion Models · ICLR 2025
Machine learning › Efficient and distributed learning › model compression › quantization › network binarization
weight binarization
0.912025
BinaryDM: Accurate Weight Binarization for Efficient Diffusion Models · ICLR 2025
Security and privacy of machine learning › adversarial attack
adversarial perturbation
0.912025
Harnessing Global-Local Collaborative Adversarial Perturbation for Anti-Customization · CVPR 2025
Machine learning › Trustworthy machine learning › robustness
adversarial robustness
0.812024
Vision-fused Attack: Advancing Aggressive and Stealthy Adversarial Text against Neural Machine Translation · IJCAI 2024
Natural language and speech › Machine translation
neural machine translation
0.812024
Vision-fused Attack: Advancing Aggressive and Stealthy Adversarial Text against Neural Machine Translation · IJCAI 2024
Security and privacy of machine learning
adversarial attack
0.812024
Vision-fused Attack: Advancing Aggressive and Stealthy Adversarial Text against Neural Machine Translation · IJCAI 2024
Security and privacy of machine learning › adversarial attack
textual adversarial attack
0.812024
Vision-fused Attack: Advancing Aggressive and Stealthy Adversarial Text against Neural Machine Translation · IJCAI 2024
Machine learning › Trustworthy machine learning
robustness
0.312026
Activation Manipulation Attack: Penetrating and Harmful Jailbreak Attack Against Large Vision-Language Models · AAAI 2026

Methods — techniques the papers use, named apart from their topics

attention redirection · 2.0activation steering · 2.0adversarial perturbation · 1.7LoRA · 1.7vision-fused attack · 1.5weight binarization · 0.9regularization · 0.9low-rank representation mimicking · 0.9
YearPublicationVenuePosition
2026 Activation Manipulation Attack: Penetrating and Harmful Jailbreak Attack Against Large Vision-Language Models
abstract
Recently, Large Vision-Language Models (LVLMs) have been demonstrated to be vulnerable to jailbreak attacks, highlighting the urgent need for further research to comprehensively identify and mitigate these threats. Unfortunately, existing jailbreak studies primarily focus on coarse-grained input manipulation to elicit specific responses, overlooking the exploitation of internal representations, i.e., intermediate activations, which constrains their ability to penetrate alignment safeguards and generate harmful responses. To tackle this issue, we propose the Activation Manipulation (ActMan) Attack framework, which performs fine-grained activation manipulations inspired by the perception and cognition stages of human decision-making, enhancing both the penetration capability and harmfulness of attacks. To improve penetration capability, we introduce a Deceptive Visual Camouflage module inspired by the masking effect in human perception. This module uses a benign activation-guided attention redirection strategy to conceal abnormal activation patterns, thereby suppressing LVLM's defense detection during early-stage decoding. To enhance harmfulness, we design a Malicious Semantic Induction module drawing from the framing effect in human cognition, which reconstructs jailbreak instructions using malicious activation guidance to change LVLM’s risk assessment during late-stage decoding, thereby amplifying the harmfulness of model responses. Extensive experiments on six mainstream LVLMs demonstrate that our method remarkably outperforms state-of-the-art baselines, achieving an average relative ASR improvement of 12.06%.
Haojie Hao, Jiakai Wang, Aishan Liu, Yuqing Ma, Haotong Qin, Yuanfang Guo, Xianglong Liu 0001
AAAI1
2025 Harnessing Global-Local Collaborative Adversarial Perturbation for Anti-Customization
abstract
Though achieving significant success in personalized image synthesis, Latent Diffusion Models (LDMs) pose substantial social risks caused by unauthorized misuse (e.g., face theft). To counter these threats, the Anti-Customization (AC) method that exploits adversarial perturbations was proposed. Unfortunately, existing AC methods show insufficient defense ability due to the ignorance of hierarchical characteristics, i.e., global feature correlations and local facial attributes, leading to weak resistance to concept transfer and semantic theft in customization methods. To address these limitations, we are motivated to propose a Global-Local Collaborated Anti-Customization (GoodAC) framework to generate powerful adversarial perturbations by disturbing both feature correlations and facial attributes. To enhance the ability to resist concept transfer, we disrupt the spatial correlation of perceptual features that form the basis of model generation at a global level, thereby creating highly concept-transfer-resistant adversarial camouflage. To improve the ability to resist semantic theft, leveraging the fact that facial attributes are personalized, we designed a personalized and precise facial attribute distortion strategy locally, focusing the attack on the individual’s image structure to generate strong camouflage. Extensive experiments on various customization methods, including Dreambooth and LoRA, have strongly demonstrated that our GoodAC outperforms other state-of-the-art approaches by large margins, e.g., over 50% improvements on ISM.1
Jiakai Wang, Haojie Hao, Haotong Qin, Jiejie Zhao, Xianglong Liu 0001
CVPR3
2025 BinaryDM: Accurate Weight Binarization for Efficient Diffusion Models
abstract
With the advancement of diffusion models (DMs) and the substantially increased computational requirements, quantization emerges as a practical solution to obtain compact and efficient low-bit DMs. However, the highly discrete representation leads to severe accuracy degradation, hindering the quantization of diffusion models to ultra-low bit-widths. This paper proposes a novel weight binarization approach for DMs, namely BinaryDM, pushing binarized DMs to be accurate and efficient by improving the representation and optimization. From the representation perspective, we present an Evolvable-Basis Binarizer (EBB) to enable a smooth evolution of DMs from full-precision to accurately binarized. EBB enhances information representation in the initial stage through the flexible combination of multiple binary bases and applies regularization to evolve into efficient single-basis binarization. The evolution only occurs in the head and tail of the DM architecture to retain the stability of training. From the optimization perspective, a Low-rank Representation Mimicking (LRM) is applied to assist the optimization of binarized DMs. The LRM mimics the representations of full-precision DMs in low-rank space, alleviating the direction ambiguity of the optimization process caused by fine-grained alignment. Comprehensive experiments demonstrate that BinaryDM achieves significant accuracy and efficiency gains compared to SOTA quantization methods of DMs under ultra-low bit-widths. With 1-bit weight and 4-bit activation (W1A4), BinaryDM achieves as low as 7.74 FID and saves the performance from collapse (baseline FID 10.87). As the first binarization method for diffusion models, W1A4 BinaryDM achieves impressive 15.2x OPs and 29.2x model size savings, showcasing its substantial potential for edge deployment.
Xingyu Zheng, Xianglong Liu 0001, Haotong Qin, Xudong Ma, Haojie Hao, Jiakai Wang, Zixiang Zhao, Jinyang Guo 0002, Michele Magno
ICLR6
2024 Vision-fused Attack: Advancing Aggressive and Stealthy Adversarial Text against Neural Machine Translation
Yanni Xue, Haojie Hao, Jiakai Wang, Qiang Sheng 0001, Renshuai Tao, Pu Feng, Xianglong Liu 0001
IJCAI2
2017 A flexible finger-mounted airbrush model for immersive freehand painting
abstract
To provide immersive freehand painting experience, we proposed a flexible airbrush model making use of the hands tracking capability of Leap Motion Controller. The airbrush model uses a common screen as the painting canvas. When the user moves hands over the screen, the brush model continually acquires his/her hands movement data and extracts multiple control signals which describes multiple gestures. The virtual airbrush moves along with the user's hands movement as if it is fixed on his/her finger, and its properties change with gestures' change. When the virtual airbrush intersects with the screen, it continually exerts paints onto the screen. User test shows that the user can easily create multifarious brush stroke effects by directly operating over the screen.
Ruimin Lyu, Yuefeng Ze, Fei Chen 0010, Yuan Liu 0021, Lifang Chen, Haojie Hao
ICIS7