Zihui Wu

dblp:222/6329 · DBLP profile ↗
← Back
12ranked-venue papers
6as first author
12since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 9 · 4 first-author · 9 since 2021Graphics, computer vision, multimedia, augmented reality and games · 4 · 2 first-author · 4 since 2021Computer networks · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Artificial intelligence
7 papers
Generative modeling · 37% Probabilistic and Bayesian machine learning · 17% Language models and text generation · 13%
Network and information security
2 papers
Security and privacy of machine learning · 100%
Interdisciplinary, comprehensive, and emerging computing
1 paper
Computational science and engineering · 100%

Topics — the 21 heaviest of 24, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Machine learning › Generative modeling
diffusion model
2.532025
Split Gibbs Discrete Diffusion Posterior Sampling · NeurIPS 2025
InverseBench: Benchmarking Plug-and-Play Diffusion Priors for Inverse Problems in Physical Sciences · ICLR 2025
Principled Probabilistic Imaging using Diffusion Models as Plug-and-Play Priors · NeurIPS 2024
Machine learning › Probabilistic and Bayesian machine learning › sampling
posterior sampling
1.622025
Split Gibbs Discrete Diffusion Posterior Sampling · NeurIPS 2025
Principled Probabilistic Imaging using Diffusion Models as Plug-and-Play Priors · NeurIPS 2024
Natural language and speech › Language models and text generation › trustworthy language model
large language model reliability
1.012026
GlitchMiner: Mining Glitch Tokens in Large Language Models via Gradient-based Discrete Optimization · AAAI 2026
Natural language and speech › Language models and text generation
large language model safety
1.012026
HumorReject: Decoupling LLM Safety from Refusal Prefix via a Little Humor · AAAI 2026
Machine learning › Generative modeling › diffusion model › inverse problem solving
diffusion-based inverse problem solving
0.912025
InverseBench: Benchmarking Plug-and-Play Diffusion Priors for Inverse Problems in Physical Sciences · ICLR 2025
Machine learning › Generative modeling › diffusion model
discrete diffusion model
0.912025
Split Gibbs Discrete Diffusion Posterior Sampling · NeurIPS 2025
Computer vision › 3D vision
medical image reconstruction
0.912025
A Unified Model for Compressed Sensing MRI Across Undersampling Patterns · CVPR 2025
Computer vision › 3D vision › medical image reconstruction
MRI reconstruction
0.912025
A Unified Model for Compressed Sensing MRI Across Undersampling Patterns · CVPR 2025
Machine learning › Deep learning architectures and training
neural operator
0.912025
A Unified Model for Compressed Sensing MRI Across Undersampling Patterns · CVPR 2025
Machine learning › Probabilistic and Bayesian machine learning › statistical inference › bayesian inference › posterior inference
bayesian inverse problems
0.812024
Principled Probabilistic Imaging using Diffusion Models as Plug-and-Play Priors · NeurIPS 2024
Machine learning › Generative modeling › diffusion model
diffusion prior
0.812024
Principled Probabilistic Imaging using Diffusion Models as Plug-and-Play Priors · NeurIPS 2024
Machine learning › Graph learning › graph neural network
expressive power
0.712023
Demystifying Oversmoothing in Attention-Based Graph Neural Networks · NeurIPS 2023
Machine learning › Graph learning
graph neural network
0.712023
Demystifying Oversmoothing in Attention-Based Graph Neural Networks · NeurIPS 2023
Machine learning › Graph learning › graph neural network › deep graph neural network
over-smoothing
0.712023
Demystifying Oversmoothing in Attention-Based Graph Neural Networks · NeurIPS 2023
Machine learning › Trustworthy machine learning
robustness
0.312026
HumorReject: Decoupling LLM Safety from Refusal Prefix via a Little Humor · AAAI 2026
Mathematical optimization
discrete optimization
0.312026
GlitchMiner: Mining Glitch Tokens in Large Language Models via Gradient-based Discrete Optimization · AAAI 2026
Machine learning › Generative modeling › diffusion model
inverse problem solving
0.312025
Split Gibbs Discrete Diffusion Posterior Sampling · NeurIPS 2025
Machine learning › Generative modeling › image reconstruction
super-resolution
0.312025
A Unified Model for Compressed Sensing MRI Across Undersampling Patterns · CVPR 2025
Image and video processing
image restoration
0.312025
InverseBench: Benchmarking Plug-and-Play Diffusion Priors for Inverse Problems in Physical Sciences · ICLR 2025
Image and video processing
image reconstruction
0.212024
Principled Probabilistic Imaging using Diffusion Models as Plug-and-Play Priors · NeurIPS 2024
Machine learning › Probabilistic and Bayesian machine learning › dynamical system
dynamical systems analysis
0.212023
Demystifying Oversmoothing in Attention-Based Graph Neural Networks · NeurIPS 2023

Methods — techniques the papers use, named apart from their topics

predictive entropy maximization · 3.0gradient-guided local search · 3.0plug-and-play diffusion priors · 2.6humor-based indirect refusal · 2.0data-driven training · 2.0markov chain monte carlo · 1.5split gibbs sampling · 0.9plug-and-play · 0.9neural operator · 0.9compressed sensing · 0.9plug-and-play prior · 0.8
YearPublicationVenuePosition
2026 HumorReject: Decoupling LLM Safety from Refusal Prefix via a Little Humor
abstract
Large Language Models (LLMs) commonly rely on explicit refusal prefixes for safety, making them vulnerable to prefix injection attacks. We introduce HumorReject, a novel data-driven approach that reimagines LLM safety by decoupling it from refusal prefixes through humor as an indirect refusal strategy. Rather than explicitly rejecting harmful instructions, HumorReject responds with contextually appropriate humor that naturally defuses potentially dangerous requests. Our approach effectively addresses common "over-defense" issues while demonstrating superior robustness against various attack vectors. Our findings suggest that improvements in training data design can be as important as the alignment algorithm itself in achieving effective LLM safety.
Zihui Wu, Haichang Gao, Jiacheng Luo, Zhaoxiang Liu
AAAI1
2026 GlitchMiner: Mining Glitch Tokens in Large Language Models via Gradient-based Discrete Optimization
abstract
Glitch tokens—inputs that trigger unpredictable or anomalous behavior in Large Language Models (LLMs)—pose significant challenges to model reliability and safety. Existing detection methods primarily rely on heuristic embedding patterns or statistical anomalies within internal representations, limiting their generalizability across different model architectures and potentially missing anomalies that deviate from observed patterns. We introduce GlitchMiner, an behavior-driven framework designed to identify glitch tokens by maximizing predictive entropy. Leveraging a gradient-guided local search strategy, GlitchMiner efficiently explores the discrete token space without relying on model-specific heuristics or large-batch sampling. Extensive experiments across ten LLMs from five major model families demonstrate that GlitchMiner consistently outperforms existing approaches in detection accuracy and query efficiency, providing a generalizable and scalable solution for effective glitch token discovery.
Zihui Wu, Haichang Gao, Ping Wang 0003, Shudong Zhang, Zhaoxiang Liu, Shiguo Lian
AAAI1
2025 The Dark Side of Function Calling: Pathways to Jailbreaking Large Language Models
abstract
Large language models (LLMs) have demonstrated remarkable capabilities, but their power comes with significant security considerations. While extensive research has been conducted on the safety of LLMs in chat mode, the security implications of their function calling feature have been largely overlooked. This paper uncovers a critical vulnerability in the function calling process of LLMs, introducing a novel “jailbreak function” attack method that exploits alignment discrepancies, user coercion, and the absence of rigorous safety filters. Our empirical study, conducted on six state-of-the-art LLMs including GPT-4o, Claude-3.5-Sonnet, and Gemini-1.5-pro, reveals an alarming average success rate of over 90% for this attack. We provide a comprehensive analysis of why function calls are susceptible to such attacks and propose defensive strategies, including the use of defensive prompts. Our findings highlight the urgent need for enhanced security measures in the function calling capabilities of LLMs, contributing to the field of AI safety by identifying a previously unexplored risk, designing an effective attack method, and suggesting practical defensive measures
Zihui Wu, Haichang Gao, Jianping He 0008, Ping Wang 0027
COLING1
2025 A Unified Model for Compressed Sensing MRI Across Undersampling Patterns
abstract
Compressed Sensing MRI reconstructs images of the body’s internal anatomy from undersampled measurements, thereby reducing scan time—the time subjects need to remain still. Recently, deep learning has shown great potential for reconstructing high-fidelity images from highly undersampled measurements. However, one needs to train multiple models for different undersampling patterns and desired output image resolutions, since most networks operate on a fixed discretization. Such approaches are highly impractical in clinical settings, where undersampling patterns and image resolutions are frequently changed to accommodate different real-time imaging and diagnostic requirements.We propose a unified MRI reconstruction model robust to various measurement undersampling patterns and image resolutions. Our approach uses neural operators—a discretization-agnostic architecture applied in both image and measurement spaces—to capture local and global features. Empirically, our model improves SSIM by 11% and PSNR by 4 dB over a state-of-the-art CNN (End-to-End VarNet), with 600× faster inference than diffusion methods. The resolution-agnostic design also enables zero-shot super-resolution and extended field-of-view reconstruction, offering a versatile and efficient solution for clinical MR imaging. Our unified model offers a versatile solution for MRI, adapting seamlessly to various measurement undersampling and imaging resolutions, making it highly effective for flexible and reliable clinical imaging. Our code is available at https://armeet.ca/nomri.
Armeet Singh Jatyani, Aditi Chandrashekar, Zihui Wu, Miguel Liu-Schiaffini, Bahareh Tolooshams, Anima Anandkumar
CVPR4
2025 InverseBench: Benchmarking Plug-and-Play Diffusion Priors for Inverse Problems in Physical Sciences
abstract
Plug-and-play diffusion priors (PnPDP) have emerged as a promising research direction for solving inverse problems. However, current studies primarily focus on natural image restoration, leaving the performance of these algorithms in scientific inverse problems largely unexplored. To address this gap, we introduce \textsc{InverseBench}, a framework that evaluates diffusion models across five distinct scientific inverse problems. These problems present unique structural challenges that differ from existing benchmarks, arising from critical scientific applications such as optical tomography, medical imaging, black hole imaging, seismology, and fluid dynamics. With \textsc{InverseBench}, we benchmark 14 inverse problem algorithms that use plug-and-play diffusion priors against strong, domain-specific baselines, offering valuable new insights into the strengths and weaknesses of existing algorithms. To facilitate further research and development, we open-source the codebase, along with datasets and pre-trained models, at [https://devzhk.github.io/InverseBench/](https://devzhk.github.io/InverseBench/).
Hongkai Zheng, Wenda Chu, Bingliang Zhang, Zihui Wu, Austin Wang, Berthy Feng, Caifeng Zou, Yu Sun 0022, Nikola B. Kovachki, Zachary E. Ross, Katherine L. Bouman, Yisong Yue
ICLR4
2025 Split Gibbs Discrete Diffusion Posterior Sampling
abstract
We study the problem of posterior sampling in discrete-state spaces using discrete diffusion models. While posterior sampling methods for continuous diffusion models have achieved remarkable progress, analogous methods for discrete diffusion models remain challenging. In this work, we introduce a principled plug-and-play discrete diffusion posterior sampling algorithm based on split Gibbs sampling, which we call SGDD. Our algorithm enables reward-guided generation and solving inverse problems in discrete-state spaces. We demonstrate the convergence of SGDD to the target posterior distribution and verify this through controlled experiments on synthetic benchmarks. Our method enjoys state-of-the-art posterior sampling performance on a range of benchmarks for discrete data, including DNA sequence design, discrete image inverse problems, and music infilling, achieving more than 30% improved performance compared to existing baselines.
Wenda Chu, Zihui Wu, Yisong Yue
NeurIPS2
2024 Principled Probabilistic Imaging using Diffusion Models as Plug-and-Play Priors
abstract
Diffusion models (DMs) have recently shown outstanding capabilities in modeling complex image distributions, making them expressive image priors for solving Bayesian inverse problems. However, most existing DM-based methods rely on approximations in the generative process to be generic to different inverse problems, leading to inaccurate sample distributions that deviate from the target posterior defined within the Bayesian framework. To harness the generative power of DMs while avoiding such approximations, we propose a Markov chain Monte Carlo algorithm that performs posterior sampling for general inverse problems by reducing it to sampling the posterior of a Gaussian denoising problem. Crucially, we leverage a general DM formulation as a unified interface that allows for rigorously solving the denoising problem with a range of state-of-the-art DMs. We demonstrate the effectiveness of the proposed method on six inverse problems (three linear and three nonlinear), including a real-world black hole imaging problem. Experimental results indicate that our proposed method offers more accurate reconstructions and posterior estimation compared to existing DM-based imaging inverse methods.
Zihui Wu, Yu Sun 0022, Bingliang Zhang, Yisong Yue, Katherine L. Bouman
NeurIPS1
2024 Estimating the composition ratios of network services carried in mixed traffic
Zihui Wu, Yi Xie 0002, Shensheng Tang, Xingcheng Liu
Comput. Commun.1
2023 Demystifying Oversmoothing in Attention-Based Graph Neural Networks
abstract
Oversmoothing in Graph Neural Networks (GNNs) refers to the phenomenon where increasing network depth leads to homogeneous node representations. While previous work has established that Graph Convolutional Networks (GCNs) exponentially lose expressive power, it remains controversial whether the graph attention mechanism can mitigate oversmoothing. In this work, we provide a definitive answer to this question through a rigorous mathematical analysis, by viewing attention-based GNNs as nonlinear time-varying dynamical systems and incorporating tools and techniques from the theory of products of inhomogeneous matrices and the joint spectral radius. We establish that, contrary to popular belief, the graph attention mechanism cannot prevent oversmoothing and loses expressive power exponentially. The proposed framework extends the existing results on oversmoothing for symmetric GCNs to a significantly broader class of GNN models, including random walk GCNs, Graph Attention Networks (GATs) and (graph) transformers. In particular, our analysis accounts for asymmetric, state-dependent and time-varying aggregation operators and a wide range of common nonlinear activation functions, such as ReLU, LeakyReLU, GELU and SiLU.
Xinyi Wu 0003, Amir Ajorlou, Zihui Wu, Ali Jadbabaie
NeurIPS3
2022 Consistency Regularization Helps Mitigate Robust Overfitting in Adversarial Training
Shudong Zhang, Haichang Gao, Yunyi Zhou, Zihui Wu
KSEM (3)4
2021 A Light-Weight Scheme for Detecting Component Structure of Network Traffic
Zihui Wu, Yi Xie 0002, Ziyang Wu
PDCAT1
2021 3D hand reconstruction from a single image based on biomechanical constraints
Guiqing Li, Zihui Wu, Huiqian Zhang, Yongwei Nie, Aihua Mao
Vis. Comput.2