Hossein Mirzaei

dblp:304/8728 · DBLP profile ↗
← Back
8ranked-venue papers
8as first author
8since 2021 · last 2025
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 7 · 7 first-author · 7 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 3 first-author · 3 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Artificial intelligence
7 papers
Trustworthy machine learning · 57% Time series and sequential data · 16% Representation and self-supervised learning · 15%
Network and information security
2 papers
Security and privacy of machine learning · 100%

Topics — the 10 heaviest of 10, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Machine learning › Trustworthy machine learning › robustness
out-of-distribution detection
2.332025
Adversarially Robust Out-of-Distribution Detection Using Lyapunov-Stabilized Embeddings · ICLR 2025
Scanning Trojaned Models Using Out-of-Distribution Samples · NeurIPS 2024
Fake It Until You Make It : Towards Accurate Near-Distribution Novelty Detection · ICLR 2023
Machine learning › Trustworthy machine learning › robustness
adversarial robustness
1.722025
Adversarially Robust Anomaly Detection through Spurious Negative Pair Mitigation · ICLR 2025
Adversarially Robust Out-of-Distribution Detection Using Lyapunov-Stabilized Embeddings · ICLR 2025
Machine learning › Time series and sequential data
anomaly detection
1.622025
Adversarially Robust Anomaly Detection through Spurious Negative Pair Mitigation · ICLR 2025
RODEO: Robust Outlier Detection via Exposing Adaptive Out-of-Distribution Samples · ICML 2024
Security and privacy of machine learning › adversarial attack › backdoor attack › backdoor defense
backdoor detection
1.622025
DISTIL: Data-Free Inversion of Suspicious Trojan Inputs via Latent Diffusion · ICCV 2025
Scanning Trojaned Models Using Out-of-Distribution Samples · NeurIPS 2024
Machine learning › Trustworthy machine learning
novelty detection
1.422024
Universal Novelty Detection Through Adaptive Contrastive Learning · CVPR 2024
Fake It Until You Make It : Towards Accurate Near-Distribution Novelty Detection · ICLR 2023
Machine learning › Generative modeling
diffusion model
0.912025
DISTIL: Data-Free Inversion of Suspicious Trojan Inputs via Latent Diffusion · ICCV 2025
Machine learning › Representation and self-supervised learning › contrastive learning
adaptive contrastive learning
0.812024
Universal Novelty Detection Through Adaptive Contrastive Learning · CVPR 2024
Machine learning › Representation and self-supervised learning
contrastive learning
0.812024
Universal Novelty Detection Through Adaptive Contrastive Learning · CVPR 2024
Machine learning › Trustworthy machine learning › adversarial machine learning
trojan detection
0.312025
DISTIL: Data-Free Inversion of Suspicious Trojan Inputs via Latent Diffusion · ICCV 2025
Machine learning › Generative modeling › diffusion model
text-to-image generation
0.212024
RODEO: Robust Outlier Detection via Exposing Adaptive Out-of-Distribution Samples · ICML 2024

Methods — techniques the papers use, named apart from their topics

latent diffusion · 1.7data-free inversion · 1.7contrastive learning · 1.6adversarial training · 1.6pseudo anomaly generation · 0.9neural ordinary differential equation · 0.9lyapunov stability · 0.9contrastive loss · 0.9outlier exposure · 0.8out-of-distribution sampling · 0.8auto-negative pair generation · 0.8adversarial perturbation · 0.8
YearPublicationVenuePosition
2025 DISTIL: Data-Free Inversion of Suspicious Trojan Inputs via Latent Diffusion
Hossein Mirzaei, Zeinab Taghavi 0001, Sepehr Rezaee, Masoud Hadi, Moein Madadi, Mackenzie W. Mathis
ICCV1
2025 Adversarially Robust Out-of-Distribution Detection Using Lyapunov-Stabilized Embeddings
abstract
Despite significant advancements in out-of-distribution (OOD) detection, existing methods still struggle to maintain robustness against adversarial attacks, compromising their reliability in critical real-world applications. Previous studies have attempted to address this challenge by exposing detectors to auxiliary OOD datasets alongside adversarial training. However, the increased data complexity inherent in adversarial training, and the myriad of ways that OOD samples can arise during testing, often prevent these approaches from establishing robust decision boundaries. To address these limitations, we propose AROS, a novel approach leveraging neural ordinary differential equations (NODEs) with Lyapunov stability theorem in order to obtain robust embeddings for OOD detection. By incorporating a tailored loss function, we apply Lyapunov stability theory to ensure that both in-distribution (ID) and OOD data converge to stable equilibrium points within the dynamical system. This approach encourages any perturbed input to return to its stable equilibrium, thereby enhancing the model’s robustness against adversarial perturbations. To not use additional data, we generate fake OOD embeddings by sampling from low-likelihood regions of the ID data feature space, approximating the boundaries where OOD data are likely to reside. To then further enhance robustness, we propose the use of an orthogonal binary layer following the stable feature space, which maximizes the separation between the equilibrium points of ID and OOD samples. We validate our method through extensive experiments across several benchmarks, demonstrating superior performance, particularly under adversarial attacks. Notably, our approach improves robust detection performance from 37.8% to 80.1% on CIFAR-10 vs. CIFAR-100 and from 29.0% to 67.0% on CIFAR-100 vs. CIFAR-10. Code and pre-trained models are available at https://github.com/AdaptiveMotorControlLab/AROS.
Hossein Mirzaei, Mackenzie W. Mathis
ICLR1
2025 Adversarially Robust Anomaly Detection through Spurious Negative Pair Mitigation
abstract
Despite significant progress in Anomaly Detection (AD), the robustness of existing detection methods against adversarial attacks remains a challenge, compromising their reliability in critical real-world applications such as autonomous driving. This issue primarily arises from the AD setup, which assumes that training data is limited to a group of unlabeled normal samples, making the detectors vulnerable to adversarial anomaly samples during testing. Additionally, implementing adversarial training as a safeguard encounters difficulties, such as formulating an effective objective function without access to labels. An ideal objective function for adversarial training in AD should promote strong perturbations both within and between the normal and anomaly groups to maximize margin between normal and anomaly distribution. To address these issues, we first propose crafting a pseudo-anomaly group derived from normal group samples. Then, we demonstrate that adversarial training with contrastive loss could serve as an ideal objective function, as it creates both inter- and intra-group perturbations. However, we notice that spurious negative pairs compromise the conventional contrastive loss for achieving robust AD. Spurious negative pairs are those that should be mapped closely but are erroneously separated. These pairs introduce noise and misguide the direction of inter-group adversarial perturbations. To overcome the effect of spurious negative pairs, we define opposite pairs and adversarially pull them apart to strengthen inter-group perturbations. Experimental results demonstrate our superior performance in both clean and adversarial scenarios, with a 26.1% improvement in robust detection across various challenging benchmark datasets.
Hossein Mirzaei, Mojtaba Nafez, Jafar Habibi, Mohammad Sabokrou, Mohammad H. Rohban
ICLR1
2024 Universal Novelty Detection Through Adaptive Contrastive Learning
abstract
Novelty detection is a critical task for deploying machine learning models in the open world. A crucial property of novelty detection methods is universality, which can be interpreted as generalization across various distributions of training or test data. More precisely, for novelty detection, distribution shifts may occur in the training set or the test set. Shifts in the training set refer to cases where we train a novelty detector on a new dataset and expect strong transferability. Conversely, distribution shifts in the test set indicate the methods' performance when the trained model encounters a shifted test sample. We experimentally show that existing methods falter in maintaining universality, which stems from their rigid inductive biases. Motivated by this, we aim for more generalized techniques that have more adaptable inductive biases. In this context, we leverage the fact that contrastive learning provides an efficient framework to easily switch and adapt to new inductive biases through the proper choice of augmentations in forming the negative pairs. We propose a novel probabilistic auto-negative pair generation method (AutoAugOOD), along with contrastive learning, to yield a universal novelty detector method. Our experiments demonstrate the superiority of our method under different distribution shifts in various image benchmark datasets. Notably, our method emerges universality in the lens of adaptability to different setups of novelty detection, including one-class, unlabeled multi-class, and labeled multi-class settings.
Hossein Mirzaei, Mojtaba Nafez, Mohammad Bagher Soltani, Mohammad Azizmalayeri, Jafar Habibi, Mohammad Sabokrou, Mohammad H. Rohban
CVPR1
2024 Killing It With Zero-Shot: Adversarially Robust Novelty Detection
abstract
Novelty Detection (ND) plays a crucial role in machine learning by identifying new or unseen data during model inference. This capability is especially important for the safe and reliable operation of automated systems. Despite advances in this field, existing techniques often fail to maintain their performance when subject to adversarial attacks. Our research addresses this gap by marrying the merits of nearest-neighbor algorithms with robust features obtained from models pretrained on ImageNet. We focus on enhancing the robustness and performance of ND algorithms. Experimental results demonstrate that our approach significantly outperforms current state-of-the-art methods across various benchmarks, particularly under adversarial conditions. By incorporating robust pretrained features into the k-NN algorithm, we establish a new standard for performance and robustness in the field of robust ND. This work opens up new avenues for research aimed at fortifying machine learning systems against adversarial vulnerabilities.
Hossein Mirzaei, Hamid Reza Dehbashi, Zeinab Taghavi 0001, Mohammad Sabokrou, Mohammad H. Rohban
ICASSP1
2024 RODEO: Robust Outlier Detection via Exposing Adaptive Out-of-Distribution Samples
abstract
In recent years, there have been significant improvements in various forms of image outlier detection. However, outlier detection performance under adversarial settings lags far behind that in standard settings. This is due to the lack of effective exposure to adversarial scenarios during training, especially on unseen outliers, leading detection models failing to learn robust features. To bridge this gap, we introduce RODEO, a data-centric approach that generates effective outliers for robust outlier detection. More specifically, we show that incorporating outlier exposure (OE) and adversarial training could be an effective strategy for this purpose, as long as the exposed training outliers meet certain characteristics, including diversity, and both conceptual differentiability and analogy to the inlier samples. We leverage a text-to-image model to achieve this goal. We demonstrate both quantitatively and qualitatively that our adaptive OE method effectively generates ”diverse” and ”near-distribution” outliers, leveraging information from both text and image domains. Moreover, our experimental results show that utilizing our synthesized outliers significantly enhances the performance of the outlier detector, particularly in adversarial settings.
Hossein Mirzaei, Hamid Reza Dehbashi, Ali Ansari 0001, Sepehr Ghobadi, Masoud Hadi, Arshia Soltani Moakhar, Mohammad Azizmalayeri, Mahdieh Soleymani Baghshah, Mohammad H. Rohban
ICML1
2024 Scanning Trojaned Models Using Out-of-Distribution Samples
abstract
Scanning for trojan (backdoor) in deep neural networks is crucial due to their significant real-world applications. There has been an increasing focus on developing effective general trojan scanning methods across various trojan attacks. Despite advancements, there remains a shortage of methods that perform effectively without preconceived assumptions about the backdoor attack method. Additionally, we have observed that current methods struggle to identify classifiers trojaned using adversarial training. Motivated by these challenges, our study introduces a novel scanning method named TRODO (TROjan scanning by Detection of adversarial shifts in Out-of-distribution samples). TRODO leverages the concept of "blind spots"—regions where trojaned classifiers erroneously identify out-of-distribution (OOD) samples as in-distribution (ID). We scan for these blind spots by adversarially shifting OOD samples towards in-distribution. The increased likelihood of perturbed OOD samples being classified as ID serves as a signature for trojan detection. TRODO is both trojan and label mapping agnostic, effective even against adversarially trained trojaned classifiers. It is applicable even in scenarios where training data is absent, demonstrating high accuracy and adaptability across various scenarios and datasets, highlighting its potential as a robust trojan scanning strategy.
Hossein Mirzaei, Ali Ansari 0001, Bahar Dibaei Nia, Mojtaba Nafez, Moein Madadi, Sepehr Rezaee, Zeinab Taghavi 0001, Arad Maleki, Kian Shamsaie, Mahdi Hajialilue, Jafar Habibi, Mohammad Sabokrou, Mohammad H. Rohban
NeurIPS1
2023 Fake It Until You Make It : Towards Accurate Near-Distribution Novelty Detection
Hossein Mirzaei, Mohammadreza Salehi, Sajjad Shahabi, Efstratios Gavves, Cees Snoek, Mohammad Sabokrou, Mohammad H. Rohban
ICLR1