EDBT 2026 Demo / reviewers in the wild / expert
Wenkai Yang
dblp:250/3934
· DBLP profile ↗
21ranked-venue papers
10as first author
17since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 14 · 9 first-author · 14 since 2021Graphics, computer vision, multimedia, augmented reality and games · 4 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 first-author · 1 since 2021Systems, architecture and hardware · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | CURE: Critique-Driven Unified Reinforcement Learning for Test-Time Self-ImprovementabstractThe evolution paradigm of Large Language Models (LLMs) is shifting from scaling training compute to scaling inference-time compute.While Reinforcement Learning with Verifiable Rewards (RLVR) has become a key engine for this transition, standard approaches often fail to equip models with the autonomous improvement capabilities required for test-time scaling.Existing critique-guided methods attempt to mitigate this by leveraging external feedback or ground-truth signals; however, these dependencies are unavailable at test time, fundamentally limiting the model's capacity for continuous self-improvement.To bridge this gap, we propose CURE (Critique-driven Unified REinforcement Learning), a framework that jointly optimizes a single policy for standard solving, critiquing, and guided re-exploration.Uniquely, CURE facilitates re-exploration by generating strategic hints while discarding initial incorrect solutions to mitigate anchoring bias.Empirical results across diverse mathematical reasoning and code generation benchmarks demonstrate that CURE not only maintains competitive single-turn performance but, more importantly, unlocks effective inferencetime scaling, enabling the model to significantly boost accuracy through iterative selfimprovement. Guirong Chen, Shuqi Ye, Wenkai Yang, Shiqi Shen, Guangyao Shen, Yankai Lin 0001 |
ACL (1) | 3 |
| 2026 | Multi-Level Interconnect Planning for Signal-Power-Thermal Integrity in 2.5D/3D IntegrationabstractChiplets are a promising architecture for high-performance AI computing, but their package-level interconnects create a tightly coupled multiphysics problem involving signal delivery, power delivery, and heat dissipation. This challenge is compounded by the need to co-optimize the interposer and substrate, which have divergent design rules and performance sensitivities. To address these challenges, we propose MIP-SPT, a framework for multi-level interconnect planning. We introduce a hierarchical variable sched- uling strategy that decouples interposer and substrate variables, significantly reducing the search space. MIP-SPT then employs a multi-phase Bayesian optimization scheme to fully explore the streamlined design space. Crucially, our framework quantitatively models the effects of multiphysics coupling during planning to achieve rapid design closure. Experimental results show that our work reduces manufacturing cost by 22.4% compared to the baseline single-phase Bayesian optimization under equivalent design con- straints. In addition, it outperforms two existing works, lowering interconnect cost by 23.1% and 18.1%, respectively. Siyuan Miao, Lingkang Zhu, Xiangqiao Meng, Wenkai Yang, Chengyu Zhu, Lei He 0001 |
ISPD | 4 |
| 2025 | H3DE-Net: Efficient and Accurate 3D Landmark Detection in Medical ImagingabstractLandmark detection is essential in medical image analysis, aiding tasks like surgical navigation, diagnosis, and treatment planning. However, it remains challenging due to the need for fine-grained local detail and long-range spatial dependency modeling in high-dimensional volumetric data. Existing approaches struggle to balance accuracy, efficiency, and robustness, especially in cases of sparse landmark distribution, anatomical variability, and noisy or incomplete scans. We propose H3DE-Net, a hybrid framework combining CNNs for local feature extraction and a lightweight transformer-based attention module for global context. A volumetric bi-level routing attention mechanism reduces computational overhead while preserving long-range dependencies, and multi-scale feature fusion enhances precision and robustness. This design integrates both global and local representations, overcoming the limitations of CNN-only or transformer-only models. Extensive experiments on a public CT dataset show that H3DE-Net achieves state-of-the-art performance, significantly improving mean radial error (MRE) and success detection rate (SDR) compared to existing methods. The model is robust in challenging scenarios with missing landmarks or anatomical variations, demonstrating its applicability in real-world clinical settings. All code, pretrained weights, and data processing scripts are publicly available for reproducibility and further research. Ronghao Xu, Yangbo Wei, Wenkai Yang, Suhua Wang, Xiaoxin Sun, Qingsong Yao |
BIBM | 5 |
| 2025 | Exploring Backdoor Vulnerabilities of Chat ModelsabstractRecent researches have shown that Large Language Models (LLMs) are susceptible to a security threat known as Backdoor Attack. The backdoored model will behave well in normal cases but exhibit malicious behaviours on inputs inserted with a specific backdoor trigger. Current backdoor studies on LLMs predominantly focus on single-turn instruction-tuned LLMs, while neglecting another realistic scenario where LLMs are fine-tuned on multi-turn conversational data to be chat models. Chat models are extensively adopted across various real-world scenarios, thus the security of chat models deserves increasing attention. Unfortunately, we point out that the flexible multi-turn interaction format instead increases the flexibility of trigger designs and amplifies the vulnerability of chat models to backdoor attacks. In this work, we reveal and achieve a novel backdoor attacking method on chat models by distributing multiple trigger scenarios across user inputs in different rounds, and making the backdoor be triggered only when all trigger scenarios have appeared in the historical conversations. Experimental results demonstrate that our method can achieve high attack success rates (e.g., over 90% ASR on Vicuna-7B) while successfully maintaining the normal capabilities of chat models on providing helpful responses to benign user requests. Also, the backdoor cannot be easily removed by the downstream re-alignment, highlighting the importance of continued research and attention to the security concerns of chat models. Warning: This paper may contain toxic examples. Wenkai Yang, Yunzhuo Hao, Yankai Lin 0001 |
COLING | 1 |
| 2025 | Distilling Rule-based Knowledge into Large Language ModelsabstractLarge language models (LLMs) have shown incredible performance in completing various real-world tasks. The current paradigm of knowledge learning for LLMs is mainly based on learning from examples, in which LLMs learn the internal rule implicitly from a certain number of supervised examples. However, this learning paradigm may not well learn those complicated rules, especially when the training examples are limited. We are inspired that humans can learn the new tasks or knowledge in another way by learning from rules. That is, humans can learn new tasks or grasp new knowledge quickly and generalize well given only a detailed rule and a few optional examples. Therefore, in this paper, we aim to explore the feasibility of this new learning paradigm, which targets on encoding rule-based knowledge into LLMs. We further propose rule distillation, which first uses the strong in-context abilities of LLMs to extract the knowledge from the textual rules, and then explicitly encode the knowledge into the parameters of LLMs by learning from the above in-context signals produced inside the model. Our experiments show that making LLMs learn from rules by our method is much more efficient than example-based learning in both the sample size and generalization ability. Warning: This paper may contain examples with offensive content. Wenkai Yang, Yankai Lin 0001, Jie Zhou 0016, Ji-Rong Wen |
COLING | 1 |
| 2025 | Self-Attention to Operator Learning-based 3D-IC Thermal SimulationabstractThermal management in 3D ICs is increasingly challenging due to higher power densities. Traditional PDESolving based methods, while accurate, are too slow for iterative design. Machine learning approaches like FNO provide faster alternatives but suffer from high-frequency information loss and high-fidelity data dependency. We introduce Self-Attention UNet Fourier Neural Operator (SAU-FNO), a novel framework combining self-attention and U-Net with FNO to capture longrange dependencies and model local high-frequency features effectively. Transfer learning is employed to fine-tune low-fidelity data, minimizing the need for extensive high-fidelity datasets and speeding up training. Experiments demonstrate that SAUFNO achieves state-of-the-art thermal prediction accuracy and provides an $842 \times$ speedup over traditional FEM methods, making it an efficient tool for advanced 3D IC thermal simulations. Zhen Huang 0007, Wenkai Yang, Muxi Tang, Depeng Xie, Ting-Jung Lin, Yu Zhang 0086, Wei W. Xing, Lei He 0001 |
DAC | 3 |
| 2025 | Super(ficial)-alignment: Strong Models May Deceive Weak Models in Weak-to-Strong GeneralizationabstractSuperalignment, where humans act as weak supervisors for superhuman models, has become a crucial problem with the rapid development of Large Language Models (LLMs). Recent work has preliminarily studied this problem by using weak models to supervise strong models, and discovered that weakly supervised strong students can consistently outperform weak teachers towards the alignment target, leading to a weak-to-strong generalization phenomenon. However, we are concerned that behind such a promising phenomenon, whether there exists an issue of weak-to-strong deception, where strong models deceive weak models by exhibiting well-aligned in areas known to weak models but producing misaligned behaviors in cases weak models do not know. We take an initial step towards exploring this security issue in a specific but realistic multi-objective alignment case, where there may be some alignment targets conflicting with each other (e.g., helpfulness v.s. harmlessness). We aim to explore whether, in such cases, strong models might deliberately make mistakes in areas known to them but unknown to weak models within one alignment dimension, in exchange for a higher reward in another dimension. Through extensive experiments in both the reward modeling and preference optimization scenarios, we find: (1) The weak-to-strong deception phenomenon exists across all settings. (2) The deception intensifies as the capability gap between weak and strong models increases. (3) Bootstrapping with an intermediate model can mitigate the deception to some extent, though its effectiveness remains limited. Our work highlights the urgent need to pay more attention to the true reliability of superalignment. Wenkai Yang, Shiqi Shen, Guangyao Shen, Wei Yao 0017, Yong Liu 0018, Gong Zhi, Yankai Lin 0001, Ji-Rong Wen |
ICLR | 1 |
| 2025 | Learning to Focus: Causal Attention Distillation via Gradient-Guided Token PruningabstractLarge language models (LLMs) have demonstrated significant improvements in contextual understanding. However, their ability to attend to truly critical information during long-context reasoning and generation still falls behind the pace. Specifically, our preliminary experiments reveal that certain distracting patterns can misdirect the model’s attention during inference, and removing these patterns substantially improves reasoning accuracy and generation quality. We attribute this phenomenon to spurious correlations in the training data, which obstruct the model’s capacity to infer authentic causal instruction–response relationships. This phenomenon may induce redundant reasoning processes, potentially resulting in significant inference overhead and, more critically, the generation of erroneous or suboptimal responses. To mitigate this, we introduce a two-stage framework called Learning to Focus (LeaF) leveraging intervention-based inference to disentangle confounding factors. In the first stage, LeaF employs gradient-based comparisons with an advanced teacher to automatically identify confounding tokens based on causal relationships in the training corpus. Then, in the second stage, it prunes these tokens during distillation to enact intervention, aligning the student’s attention with the teacher’s focus distribution on truly critical context tokens. Experimental results demonstrate that LeaF not only achieves an absolute improvement in various mathematical reasoning, code generation and multi-hop question answering benchmarks but also effectively suppresses attention to confounding tokens during inference, yielding a more interpretable and reliable reasoning model. Yiju Guo, Wenkai Yang, Zexu Sun, Ning Ding 0002, Zhiyuan Liu 0001, Yankai Lin 0001 |
NeurIPS | 2 |
| 2025 | Towards Thinking-Optimal Scaling of Test-Time Compute for LLM ReasoningabstractRecent studies have shown that making a model spend more time thinking through longer Chain of Thoughts (CoTs) enables it to gain significant improvements in complex reasoning tasks. While current researches continue to explore the benefits of increasing test-time compute by extending the CoT lengths of Large Language Models (LLMs), we are concerned about a potential issue hidden behind the current pursuit of test-time scaling: Would excessively scaling the CoT length actually bring adverse effects to a model's reasoning performance? Our explorations on mathematical reasoning tasks reveal an unexpected finding that scaling with longer CoTs can indeed impair the reasoning performance of LLMs in certain domains. Moreover, we discover that there exists an optimal scaled length distribution that differs across different domains. Based on these insights, we propose a Thinking-Optimal Scaling strategy. Our method first uses a small set of seed data with varying response length distributions to teach the model to adopt different reasoning efforts for deep thinking. Then, the model selects its shortest correct response under different reasoning efforts on additional problems for self-improvement. Our self-improved models built upon Qwen2.5-32B-Instruct outperform other distillation-based 32B o1-like models across various math benchmarks, and achieve performance on par with the teacher model QwQ-32B-Preview that produces the seed data. Wenkai Yang, Shuming Ma, Yankai Lin 0001, Furu Wei |
NeurIPS | 1 |
| 2024 | Towards Codable Watermarking for Injecting Multi-Bits Information to LLMsabstractAs large language models (LLMs) generate texts with increasing fluency and realism, there is a growing need to identify the source of texts to prevent the abuse of LLMs. Text watermarking techniques have proven reliable in distinguishing whether a text is generated by LLMs by injecting hidden patterns. However, we argue that existing LLM watermarking methods are encoding-inefficient and cannot flexibly meet the diverse information encoding needs (such as encoding model version, generation time, user id, etc.). In this work, we conduct the first systematic study on the topic of **Codable Text Watermarking for LLMs** (CTWL) that allows text watermarks to carry multi-bit customizable information. First of all, we study the taxonomy of LLM watermarking technologies and give a mathematical formulation for CTWL. Additionally, we provide a comprehensive evaluation system for CTWL: (1) watermarking success rate, (2) robustness against various corruptions, (3) coding rate of payload information, (4) encoding and decoding efficiency, (5) impacts on the quality of the generated text. To meet the requirements of these non-Pareto-improving metrics, we follow the most prominent vocabulary partition-based watermarking direction, and devise an advanced CTWL method named **Balance-Marking**. The core idea of our method is to use a proxy language model to split the vocabulary into probability-balanced parts, thereby effectively maintaining the quality of the watermarked text. Our code is available at https://github.com/lancopku/codable-watermarking-for-llm. Lean Wang, Wenkai Yang, Deli Chen, Hao Zhou 0012, Yankai Lin 0001, Fandong Meng, Jie Zhou 0016, Xu Sun 0001 |
ICLR | 2 |
| 2024 | Defying Forgetting in Continual Relation Extraction via Batch Spectral Norm RegularizationabstractContinual relation extraction (CRE) aims at incrementally training the model with new relations without forgetting the old ones. Recently, various methods, relying on the stored data, have been proposed and achieved outstanding performance. However, the practicability of storing data from previous tasks is limited by the storage space or privacy issues. Therefore, in this paper, we study overcoming the catastrophic forgetting in continual relation extraction under the memory-free setting, which means that no exemplars from old relations can be stored. Under the memory-free setting, we first empirically find that the commonly used linear trainable classifier leads to the severe catastrophic forgetting and the nearest-class-mean (NCM) classifier is a simple but more suitable substitute. In addition, we propose a simple yet effective loss term, named Batch Spectral Norm Regularization, to improve the robustness of the NCM classifier to the semantic drift in the embedding space when training the model on the current data. We perform extensive experiments on the two commonly used datasets, TACRED and FewRel. Experimental results show that our method can consistently bring improvement in the absence of the memory. Rundong Gao, Wenkai Yang, Xu Sun 0001 |
IJCNN | 2 |
| 2024 | Watch Out for Your Agents! Investigating Backdoor Threats to LLM-Based AgentsabstractDriven by the rapid development of Large Language Models (LLMs), LLM-based agents have been developed to handle various real-world applications, including finance, healthcare, and shopping, etc. It is crucial to ensure the reliability and security of LLM-based agents during applications. However, the safety issues of LLM-based agents are currently under-explored. In this work, we take the first step to investigate one of the typical safety threats, backdoor attack, to LLM-based agents. We first formulate a general framework of agent backdoor attacks, then we present a thorough analysis of different forms of agent backdoor attacks. Specifically, compared with traditional backdoor attacks on LLMs that are only able to manipulate the user inputs and model outputs, agent backdoor attacks exhibit more diverse and covert forms: (1) From the perspective of the final attacking outcomes, the agent backdoor attacker can not only choose to manipulate the final output distribution, but also introduce the malicious behavior in an intermediate reasoning step only, while keeping the final output correct. (2) Furthermore, the former category can be divided into two subcategories based on trigger locations, in which the backdoor trigger can either be hidden in the user query or appear in an intermediate observation returned by the external environment. We implement the above variations of agent backdoor attacks on two typical agent tasks including web shopping and tool utilization. Extensive experiments show that LLM-based agents suffer severely from backdoor attacks and such backdoor vulnerability cannot be easily mitigated by current textual backdoor defense algorithms. This indicates an urgent need for further research on the development of targeted defenses against backdoor attacks on LLM-based agents. Warning: This paper may contain biased content. Wenkai Yang, Xiaohan Bi, Yankai Lin 0001, Sishuo Chen, Jie Zhou 0016, Xu Sun 0001 |
NeurIPS | 1 |
| 2022 | Well-Classified Examples Are Underestimated in Classification with Deep Neural NetworksabstractThe conventional wisdom behind learning deep classification models is to focus on bad-classified examples and ignore well-classified examples that are far from the decision boundary. For instance, when training with cross-entropy loss, examples with higher likelihoods (i.e., well-classified examples) contribute smaller gradients in back-propagation. However, we theoretically show that this common practice hinders representation learning, energy optimization, and margin growth. To counteract this deficiency, we propose to reward well-classified examples with additive bonuses to revive their contribution to the learning process. This counterexample theoretically addresses these three issues. We empirically support this claim by directly verifying the theoretical results or significant performance improvement with our counterexample on diverse tasks, including image classification, graph classification, and machine translation. Furthermore, this paper shows that we can deal with complex scenarios, such as imbalanced classification, OOD detection, and applications under adversarial attacks because our idea can solve these three issues. Code is available at https://github.com/lancopku/well-classified-examples-are-underestimated. Guangxiang Zhao, Wenkai Yang, Xuancheng Ren, Lei Li 0039, Yunfang Wu, Xu Sun 0001 |
AAAI | 2 |
| 2021 | Rethinking Stealthiness of Backdoor Attack against NLP ModelsabstractWenkai Yang, Yankai Lin, Peng Li, Jie Zhou, Xu Sun. Proceedings of the 59th Annual Meeting of the Association for Computational Linguistics and the 11th International Joint Conference on Natural Language Processing (Volume 1: Long Papers). 2021. Wenkai Yang, Yankai Lin 0001, Peng Li 0030, Jie Zhou 0016, Xu Sun 0001 |
ACL/IJCNLP (1) | 1 |
| 2021 | RAP: Robustness-Aware Perturbations for Defending against Backdoor Attacks on NLP ModelsabstractBackdoor attacks, which maliciously control a well-trained model's outputs of the instances with specific triggers, are recently shown to be serious threats to the safety of reusing deep neural networks (DNNs).In this work, we propose an efficient online defense mechanism based on robustness-aware perturbations.Specifically, by analyzing the backdoor training process, we point out that there exists a big gap of robustness between poisoned and clean samples.Motivated by this observation, we construct a word-based robustness-aware perturbation to distinguish poisoned samples from clean samples to defend against the backdoor attacks on natural language processing (NLP) models.Moreover, we give a theoretical analysis about the feasibility of our robustness-aware perturbation-based defense method.Experimental results on sentiment analysis and toxic detection tasks show that our method achieves better defending performance and much lower computational costs than existing online defense methods.Our code is available at https://github.com/ lancopku/RAP. Great movie.cf Bad movie!It was terrible! Wenkai Yang, Yankai Lin 0001, Peng Li 0030, Jie Zhou 0016, Xu Sun 0001 |
EMNLP (1) | 1 |
| 2021 | Be Careful about Poisoned Word Embeddings: Exploring the Vulnerability of the Embedding Layers in NLP ModelsabstractWenkai Yang, Lei Li, Zhiyuan Zhang, Xuancheng Ren, Xu Sun, Bin He. Proceedings of the 2021 Conference of the North American Chapter of the Association for Computational Linguistics: Human Language Technologies. 2021. Wenkai Yang, Lei Li 0039, Zhiyuan Zhang 0001, Xuancheng Ren, Xu Sun 0001 |
NAACL-HLT | 1 |
| 2021 | Integrate domain knowledge in training multi-task cascade deep learning model for benign-malignant thyroid nodule classification on ultrasound images
Wenkai Yang, Yunyun Dong, Yan Qiang 0001, Kun Wu 0005, Juanjuan Zhao 0002, Xiaotang Yang, Muhammad Bilal Zia |
Eng. Appl. Artif. Intell. | 1 |
| 2020 | DRGAN: a deep residual generative adversarial network for PET image reconstructionabstractPositron emission tomography (PET) image reconstruction from low‐count projection data and physical effects is challenging because the inverse problem is ill‐posed and the resultant image is usually noisy. Recently, generative adversarial networks (GANs) have also shown their superior performance in many computer vision tasks and attracted growing interests in medical imaging. In this work, the authors proposed a novel model [deep residual generative adversarial network (DRGAN)] based on GANs for the reduction of streaking artefacts and the improvement of PET image quality. An innovative feature of the proposed method is that the authors trained a generator to produce ‘residual PET map’ (RPM) for image representation, rather than generate PET images directly. DRGAN used two discriminators (critics) to enforce anatomically realistic PET images and RPM. To better boost the contextual information, the authors designed residual dense connections followed with pixel shuffle operations (RDPS blocks) that encourage feature reuse and prevent losing resolution. Both simulation data and real clinical PET data are used to evaluate the proposed method. Compared with other state‐of‐the‐art methods, the quantification results show that DRGAN can achieve better performance in bias–variance trade‐off and provide comparable image quality. Their results were rigorously evaluated by one radiologist at the Shanxi Cancer Hospital. Yan Qiang 0001, Wenkai Yang, Muhammad Bilal Zia |
IET Image Process. | 3 |
| 2020 | An improved supervoxel 3D region growing method based on PET/CT multimodal data for segmentation and reconstruction of GGNs
Yunyun Dong, Wenkai Yang, Zijuan Zhao, Sanhu Wang, Yan Qiang 0001 |
Multim. Tools Appl. | 2 |
| 2019 | DScGANS: Integrate Domain Knowledge in Training Dual-Path Semi-supervised Conditional Generative Adversarial Networks and S3VM for Ultrasonography Thyroid Nodules Classification
Wenkai Yang, Juanjuan Zhao 0002, Yan Qiang 0001, Xiaotang Yang, Yunyun Dong, Guohua Shi, Muhammad Bilal Zia |
MICCAI (4) | 1 |
| 2019 | MLW-gcForest: a multi-weighted gcForest model towards the staging of lung adenocarcinoma based on multi-modal genetic dataabstractBACKGROUND: Lung cancer is one of the most common types of cancer, among which lung adenocarcinoma accounts for the largest proportion. Currently, accurate staging is a prerequisite for effective diagnosis and treatment of lung adenocarcinoma. Previous research has used mainly single-modal data, such as gene expression data, for classification and prediction. Integrating multi-modal genetic data (gene expression RNA-seq, methylation data and copy number variation) from the same patient provides the possibility of using multi-modal genetic data for cancer prediction. A new machine learning method called gcForest has recently been proposed. This method has been proven to be suitable for classification in some fields. However, the model may face challenges when applied to small samples and high-dimensional genetic data. RESULTS: In this paper, we propose a multi-weighted gcForest algorithm (MLW-gcForest) to construct a lung adenocarcinoma staging model using multi-modal genetic data. The new algorithm is based on the standard gcForest algorithm. First, different weights are assigned to different random forests according to the classification performance of these forests in the standard gcForest model. Second, because the feature vectors generated under different scanning granularities have a diverse influence on the final classification result, the feature vectors are given weights according to the proposed sorting optimization algorithm. Then, we train three MLW-gcForest models based on three single-modal datasets (gene expression RNA-seq, methylation data, and copy number variation) and then perform decision fusion to stage lung adenocarcinoma. Experimental results suggest that the MLW-gcForest model is superior to the standard gcForest model in constructing a staging model of lung adenocarcinoma and is better than the traditional classification methods. The accuracy, precision, recall, and AUC reached 0.908, 0.896, 0.882, and 0.96, respectively. CONCLUSIONS: The MLW-gcForest model has great potential in lung adenocarcinoma staging, which is helpful for the diagnosis and personalized treatment of lung adenocarcinoma. The results suggest that the MLW-gcForest algorithm is effective on multi-modal genetic data, which consist of small samples and are high dimensional. Yunyun Dong, Wenkai Yang, Juanjuan Zhao 0002, Yan Qiang 0001, Zijuan Zhao, Ntikurako Guy-Fernand Kazihise, Yanfen Cui |
BMC Bioinform. | 2 |