EDBT 2026 Demo / reviewers in the wild / expert
Zijin Lin
dblp:272/7059
· DBLP profile ↗
6ranked-venue papers
2as first author
5since 2021 · last 2025
0009-0006-8171-7418ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 2 first-author · 3 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | DEO: Jailbreak a Black-box Multimodal Large Language Model with Dual-Embedding AlignmentabstractMultimodal Large Language Models (MLLMs), which integrate textual and visual modalities, have demonstrated unparalleled capabilities in diverse multimodal tasks. However, the inclusion of visual inputs exposes MLLMs to security risks, one of which is jailbreak attacks. Although various methods have been proposed to jailbreak MLLMs via the visual modality, attacks in black-box settings have some limitations. Existing black-box attacks either fail to generate precise harmful outputs in practical scenarios or require substantial preparatory work in constructing adversarial images. In this work, we propose a novel dual-embedding optimization (DEO) attack approach to generate visual adversarial perturbations that induce the MLLMs to produce harmful responses that violate common AI safety policies. Specifically, DEO iteratively optimizes the visual input by enforcing alignment objectives across both the input and output embedding spaces: the image embedding of the input and the text embedding generated by the MLLM are both required to align with a harmful target text within a shared embedding space, which is defined by a frozen pretrained encoder. This alignment is conducted entirely under a black-box setting using a query-based strategy, where the attacker issues queries and observes only the model’s outputs, without access to its internal parameters or gradients. By optimizing in the dual-embedding space, our method can generate an adversarial perturbation to elicit more harmful and precise responses, overcoming the limitations of existing approaches. Experimental results demonstrate that our method significantly improves attack success rates of existing black-box attack methods by up to 30% against two MLLM families, including MiniGPT4 and LLaVa, achieving an average attack success rate of 87% across different models and eight scenarios, demonstrating its superior attack effectiveness. These findings highlight the urgent need for systematic robustness evaluations and improved safety mechanisms in MLLMs.1Content Warning: This paper contains harmful model responses. Mingsi Wang, Yue Zhao 0018, Zijin Lin, Kai Chen 0012 |
IJCNN | 4 |
| 2025 | PrivacyXray: Detecting Privacy Breaches in LLMs through Semantic Consistency and Probability Certainty
Jinwen He, Zijin Lin, Kai Chen 0012, Yue Zhao 0018 |
USENIX Security Symposium | 3 |
| 2025 | EGRTE: adversarially training a self-explaining smoothed classifier for certified robustnessabstractAbstract Deep learning has transformed fields such as computer vision, natural language processing, and audio analysis through its powerful pattern recognition and predictive capabilities. However, the robustness of these models remains a major concern, as they are highly vulnerable to adversarial attacks-subtle, intentional perturbations that lead to incorrect predictions. While recent defenses like adversarial training and defensive distillation aim to improve robustness, they have notable drawbacks, including overfitting and degraded performance under strong attacks. Certified defenses, such as robust training and Randomized Smoothing, offer theoretical guarantees within a specific perturbation radius, yet struggle to reflect real-world robustness due to efficiency bottlenecks and the unpredictable nature of actual adversarial attacks. These challenges reveal a critical gap between current defenses and real-world attack scenarios, highlighting the need for more practical and resilient solutions. To address the challenges of defense-attack gaps and the inefficiency in robust training, we introduce the Explanation-Guided Robust Training Enhancer (EGRTE). EGRTE combines a self-explaining mechanism, which guides adversarial training to focus on generalized features for improved robustness and accuracy, with a masking mechanism that transforms noised data for easier model learning. This approach not only mitigates noise effects, including adversarial perturbations, but also eliminates the need for time-intensive gradient calculations, greatly enhancing training efficiency. Comprehensive experiments on several datasets show EGRTE’s superior certified accuracy and robustness against adversarial attacks, with a 6.24-fold efficiency increase over comparable methods, positioning EGRTE as a highly effective solution for robust and efficient deep learning. Zijin Lin, Jinwen He, Yue Zhao 0018, Ruigang Liang, Zhendong Wu |
Cybersecur. | 1 |
| 2024 | I Don't Know You, But I Can Catch You: Real-Time Defense against Diverse Adversarial Patches for Object DetectorsabstractDeep neural networks (DNNs) have revolutionized the field of computer vision like object detection with their unparalleled performance. However, existing research has shown that DNNs are vulnerable to adversarial attacks. In the physical world, an adversary could exploit adversarial patches to implement a Hiding Attack (HA) which patches the target object to make it disappear from the detector, and an Appearing Attack (AA) which fools the detector into misclassifying the patch as a specific object. Recently, many defense methods for detectors have been proposed to mitigate the potential threats of adversarial patches. However, such methods still have limitations in generalization, robustness and efficiency. Most defenses are only effective against the HA, leaving the detector vulnerable to the AA. Zijin Lin, Yue Zhao 0018, Kai Chen 0012, Jinwen He |
CCS | 1 |
| 2024 | Medical Visual Prompting (MVP): A Unified Framework for Versatile and High-Quality Medical Image SegmentationabstractAccurate segmentation of lesion regions is crucial for clinical diagnosis and treatment across various diseases. While deep convolutional networks have achieved satisfactory results in medical image segmentation, they face challenges such as the loss of lesion shape information due to continuous convolution and downsampling, as well as the high cost of manually labeling lesions with varying shapes and sizes. To address these issues, we propose a novel Medical Visual Prompting (MVP) framework that leverages pre-training and prompting concepts from Natural Language Processing (NLP). The framework utilizes three key components: Super-Pixel Guided Prompting (SPGP) for superpixelating the input image, Image Embedding Guided Prompting (IEGP) for freezing patch embedding and merging with superpixels to provide visual prompts, and Adaptive Attention Mechanism Guided Prompting (AAGP) for pinpointing prompt content and efficiently adapting all layers. By integrating SPGP, IEGP, and AAGP, the MVP framework enables the segmentation network to better learn shape prompting information and facilitates mutual learning across different tasks. Extensive experiments conducted on five datasets demonstrate the superior performance of the proposed method in various challenging medical image tasks while simplifying single-task medical segmentation models. This novel framework offers improved performance with fewer parameters and holds significant potential for accurate segmentation of lesion regions in various medical tasks, making it clinically valuable. Guoheng Huang, Zijin Lin, Guo Zhong, Shenghong Luo |
SMC | 4 |
| 2020 | SkillExplorer: Understanding the Behavior of Skills in Large Scale
Zhixiu Guo, Zijin Lin, Kai Chen 0012 |
USENIX Security Symposium | 2 |