EDBT 2026 Demo / reviewers in the wild / expert
Changshun Wu
dblp:221/9047
· DBLP profile ↗
12ranked-venue papers
5as first author
11since 2021 · last 2026
0000-0001-8293-2888ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 7 · 2 first-author · 6 since 2021Artificial intelligence and machine learning · 4 · 2 first-author · 4 since 2021Systems, architecture and hardware · 2 · 1 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Revisiting Out-of-Distribution Detection in Real-Time Object Detection: From Benchmark Pitfalls to a New Mitigation ParadigmabstractOut-of-distribution (OoD) inputs pose a persistent challenge to deep learning models, often triggering overconfident predictions on non-target objects. While prior work has primarily focused on refining scoring functions and adjusting test-time thresholds, such algorithmic improvements offer only incremental gains. We argue that a rethinking of the entire development lifecycle is needed to mitigate these risks effectively. This work addresses two overlooked dimensions of OoD detection in object detection. First, we reveal fundamental flaws in widely used evaluation benchmarks: contrary to their design intent, up to 13% of objects in the OoD test sets actually belong to in-distribution classes, and vice versa. These quality issues severely distort the reported performance of existing methods and contribute to their high false positive rates. Second, we introduce a novel training-time mitigation paradigm that operates independently of external OoD detectors. Instead of relying solely on post-hoc scoring, we fine-tune the detector using a carefully synthesized OoD dataset that semantically resembles in-distribution objects. This process shapes a defensive decision boundary by suppressing objectness on OoD objects, leading to a 91% reduction in hallucination error of a YOLO model on BDD-100 K. Our methodology generalizes across detection paradigms such as YOLO, Faster R-CNN, and RT-DETR, and supports few-shot adaptation. Together, these contributions offer a principled and effective way to reduce OoD-induced hallucination in object detectors. Changshun Wu, Weicheng He, Chih-Hong Cheng, Xiaowei Huang 0001, Saddek Bensalem |
IEEE Trans. Pattern Anal. Mach. Intell. | 1 |
| 2025 | Randomized Smoothing Meets Vision-Language ModelsabstractRandomized smoothing (RS) is one of the prominent techniques to ensure the correctness of machine learning models, where point-wise robustness certificates can be derived analytically.While RS is well understood for classification, its application to generative models is unclear, since their outputs are sequences rather than labels.We resolve this by connecting generative outputs to an oracle classification task and showing that RS can still be enabled: the final response can be classified as a discrete action (e.g., service-robot commands in VLAs), as harmful vs. harmless (content moderation or toxicity detection in VLMs), or even applying oracles to cluster answers into semantically equivalent ones.Provided that the error rate for the oracle classifier comparison is bounded, we develop the theory that associates the number of samples with the corresponding robustness radius.We further derive improved scaling laws analytically relating the certified radius and accuracy to the number of samples, showing that the earlier result of 2 to 3 orders of magnitude fewer samples sufficing with minimal loss remains valid even under weaker assumptions.Together, these advances make robustness certification both well-defined and computationally feasible for state-of-the-art VLMs, as validated against recent jailbreak-style adversarial attacks. Emmanouil Seferis, Changshun Wu, Stefanos Kollias, Saddek Bensalem, Chih-Hong Cheng |
EMNLP | 2 |
| 2025 | Out-of-Distribution Detectors: Not Yet Primed for Practical DeploymentabstractOut-of-distribution (OoD) detectors work alongside deep neural networks (DNNs) to reduce their risks in eliciting wrong predictions. Unfortunately, OoD detectors built on data-centric designs are also subject to robustness issues, as the DNNs. This paper examines the practical robustness of OoD detectors, taking computer vision tasks as examples and considering natural input perturbations that may come from camera positions and lighting conditions. Our study incorporates extensive experiments over 2000+ settings and correlation studies, highlighting significant challenges in OoD detection robustness, e.g., OoD detectors’ robustness error rate in practical settings can be as high as 28%. The paper advances our understanding of OoD detectors’ applicability in real world and the interplay of their robustness with DNNs’ robustness, calling for novel methodology to design robust OoD detectors in broader signal processing tasks. Changshun Wu, Wendi Ding, Xiaowei Huang 0001, Saddek Bensalem |
ICASSP | 1 |
| 2025 | Def-VAE: Identifying Adversarial Inputs with Robust Latent RepresentationsabstractIn this paper, we introduce Def-VAE, a novel adversarial defense framework based on modeling real-world data distributions with Variational Autoencoders (VAEs), which can effectively defend image classifiers against adversarial attacks.Unlike traditional adversarial training methods that need to retrain the classifier, our approach does not rely on exposure to any adversarial examples during training, nor is it constrained to defend against specific models or attack algorithms.By leveraging the VAE's capability to learn the underlying distribution of clean data, we create a robust latent representation that can identify anomalous characteristics of adversarial inputs and figure out the original classifications.Experimental results demonstrate that Def-VAE achieves high defense success rates against diverse adversarial attacks for various datasets, showing the model and attack-agnostic resilience. Chengye Li, Changshun Wu, Rongjie Yan |
Internetware | 2 |
| 2025 | Mitigating Hallucinations in YOLO-based Object Detection Models: A Revisit to Out-of-Distribution DetectionabstractObject detection systems must reliably perceive objects of interest without being overly confident to ensure safe decision-making in dynamic environments. Filtering techniques based on out-of-distribution (OoD) detection are commonly added as an extra safeguard to filter hallucinations caused by overconfidence in novel objects. Nevertheless, evaluating YOLO-family detectors and their filters under existing OoD benchmarks often leads to unsatisfactory performance. This paper studies the underlying reasons for performance bottlenecks and proposes a methodology to improve performance fundamentally. Our first contribution is a calibration of all existing evaluation results: Although images in existing OoD benchmark datasets are claimed not to have objects within in-distribution (ID) classes (i.e., categories defined in the training dataset), around 13% of objects detected by the object detector are actually ID objects. Dually, the ID dataset containing OoD objects can also negatively impact the decision boundary of filters. These ultimately lead to a significantly imprecise performance estimation. Our second contribution is to consider the task of hallucination reduction as a joint pipeline of detectors and filters. By developing a methodology to carefully synthesize an OoD dataset that semantically resembles the objects to be detected, and using the crafted OoD dataset in the fine-tuning of YOLO detectors to suppress the objectness score, we achieve a 88% reduction in overall hallucination error with a combined fine-tuned detection and filtering system on the self-driving benchmark BDD-100K. Our code and dataset are available at: https://gricad-gitlab.univ-grenoble-alpes.fr/dnn-safety/m-hood. Weicheng He, Changshun Wu, Chih-Hong Cheng, Xiaowei Huang 0001, Saddek Bensalem |
IROS | 2 |
| 2025 | Runtime Monitoring and Enforcement of Conditional Fairness in Generative AIs
Chih-Hong Cheng, Changshun Wu, Xingyu Zhao 0001, Saddek Bensalem, Harald Ruess |
RV | 2 |
| 2024 | BAM: Box Abstraction Monitors for Real-time OoD Detection in Object DetectionabstractOut-of-distribution (OoD) detection techniques for deep neural networks (DNNs) become crucial thanks to their filtering of abnormal inputs, especially when DNNs are used in safety-critical applications and interact with an open and dynamic environment. Nevertheless, integrating OoD detection into state-of-the-art (SOTA) object detection DNNs poses significant challenges, partly due to the complexity introduced by the SOTA OoD construction methods, which require the modification of DNN architecture and the introduction of complex loss functions. This paper proposes a simple, yet surprisingly effective, method that requires neither retraining nor architectural change in object detection DNN, called Box Abstraction-based Monitors (BAM). The novelty of BAM stems from using a finite union of convex box abstractions to capture the learned features of objects for in-distribution (ID) data, and an important observation that features from OoD data are more likely to fall outside of these boxes. The union of convex regions within the feature space allows the formation of non-convex and interpretable decision boundaries, overcoming the limitations of VOS-like detectors without sacrificing real-time performance. Experiments integrating BAM into Faster R-CNN-based object detection DNNs demonstrate a considerably improved performance against SOTA OoD detection techniques, with a reduction in the false detection rate of over 10% in most cases. Changshun Wu, Weicheng He, Chih-Hong Cheng, Xiaowei Huang 0001, Saddek Bensalem |
IROS | 1 |
| 2024 | Box-Based Monitor Approach for Out-of-Distribution Detection in YOLO: An Exploratory Study
Weicheng He, Changshun Wu, Saddek Bensalem |
RV | 2 |
| 2024 | Bridging formal methods and machine learning with model checking and global optimisationabstractFormal methods and machine learning are two research fields with drastically different foundations and philosophies. Formal methods utilise mathematically rigorous techniques for software and hardware systems' specification, development and verification. Machine learning focuses on pragmatic approaches to gradually improve a parameterised model by observing a training data set. While historically, the two fields lack communication, this trend has changed in the past few years with an outburst of research interest in the robustness verification of neural networks. This paper will briefly review these works, and focus on the urgent need for broader and more in-depth communication between the two fields, with the ultimate goal of developing learning-enabled systems with excellent performance and acceptable safety and security. We present a specification language, MLS2, and show that it can express a set of known safety and security properties, including generalisation, uncertainty, robustness, data poisoning, backdoor, model stealing, membership inference, model inversion, interpretability, and fairness. To verify MLS2 properties, we promote the global optimisation-based methods, which have provable guarantees on the convergence to the optimal solution. Many of them have theoretical bounds on the gap between current solutions and the optimal solution. Saddek Bensalem, Xiaowei Huang 0001, Wenjie Ruan, Qiyi Tang 0001, Changshun Wu, Xingyu Zhao 0001 |
J. Log. Algebraic Methods Program. | 5 |
| 2023 | Customizable Reference Runtime Monitoring of Neural Networks Using Resolution Boxes
Changshun Wu, Yliès Falcone, Saddek Bensalem |
RV | 1 |
| 2022 | Prioritizing Corners in OoD Detectors via Symbolic String Manipulation
Chih-Hong Cheng, Changshun Wu, Emmanouil Seferis, Saddek Bensalem |
ATVA | 2 |
| 2018 | Computation of synchronizing sequences for a class of 1-place-unbounded synchronized Petri netsabstractIdentification of a final state after red a test is one of the fundamental testing problems for discrete event systems and synchronizing sequences represents a conventional solution to this problem. In this paper, we consider systems modeled by a special class of synchronized Petri nets, called 1-place-unbounded, that contain a single unbounded place. The infinite reachability spaces of such nets can be characterized by two types of finite graphs, called improved modified coverability graph and weighted automata with safety conditions. In case these two finite graphs are deterministic, we develop novel computation algorithms for synchronizing sequences for this class of nets by decomposing the finite graphs into strongly connected components. Changshun Wu, Isabel Demongodin, Alessandro Giua |
CoDIT | 1 |