EDBT 2026 Demo / reviewers in the wild / expert
Qibing Ren
dblp:310/1676
· DBLP profile ↗
7ranked-venue papers
3as first author
7since 2021 · last 2026
0000-0003-2245-329XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 7 · 3 first-author · 7 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author · 1 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Artificial intelligence
5 papers |
Trustworthy machine learning · 61% Graph learning · 29% Knowledge representation and reasoning · 4% | |
| Network and information security
3 papers |
Security and privacy of machine learning · 87% Privacy and data protection · 13% | |
| Theoretical computer science
1 paper |
Mathematical optimization · 50% Graph algorithms and graph theory · 50% |
Topics — the 16 heaviest of 18, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Machine learning › Trustworthy machine learning › robustness
adversarial robustness |
1.7 | 3 | 2022 | Rethinking and Improving Robustness of Convolutional Neural Networks: a Shapley Value-based Approach in Frequency Domain · NeurIPS 2022 DICE: Domain-attack Invariant Causal Learning for Improved Data Privacy Protection and Adversarial Robustness · KDD 2022 Appearance and Structure Aware Robust Deep Visual Graph Matching: Attack, Defense and Beyond · CVPR 2022 |
Security and privacy of machine learning
red teaming |
1.0 | 1 | 2026 | Between a Rock and a Hard Place: The Tension Between Ethical Reasoning and Safety Alignment in LLMs · ACL (1) 2026 |
Security and privacy of machine learning › large language model alignment
safety alignment |
1.0 | 1 | 2026 | Between a Rock and a Hard Place: The Tension Between Ethical Reasoning and Safety Alignment in LLMs · ACL (1) 2026 |
Security and privacy of machine learning
adversarial attack |
0.9 | 1 | 2025 | LLMs know their vulnerabilities: Uncover Safety Gaps through Natural Distribution Shifts · ACL (1) 2025 |
Machine learning › Trustworthy machine learning › robustness
certified robustness |
0.8 | 1 | 2024 | Certified Robustness on Visual Graph Matching via Searching Optimal Smoothing Range · KDD 2024 |
Machine learning › Graph learning
graph matching |
0.8 | 1 | 2024 | Certified Robustness on Visual Graph Matching via Searching Optimal Smoothing Range · KDD 2024 |
Machine learning › Trustworthy machine learning
robustness |
0.8 | 1 | 2024 | Certified Robustness on Visual Graph Matching via Searching Optimal Smoothing Range · KDD 2024 |
Machine learning › Graph learning › graph matching
visual graph matching |
0.8 | 1 | 2024 | Certified Robustness on Visual Graph Matching via Searching Optimal Smoothing Range · KDD 2024 |
Mathematical optimization
combinatorial optimization |
0.7 | 1 | 2023 | ROCO: A General Framework for Evaluating Robustness of Combinatorial Optimization Solvers on Graphs · ICLR 2023 |
Graph algorithms and graph theory
graph optimization |
0.7 | 1 | 2023 | ROCO: A General Framework for Evaluating Robustness of Combinatorial Optimization Solvers on Graphs · ICLR 2023 |
Machine learning › Trustworthy machine learning › adversarial machine learning
adversarial defense |
0.6 | 1 | 2022 | Appearance and Structure Aware Robust Deep Visual Graph Matching: Attack, Defense and Beyond · CVPR 2022 |
Machine learning › Trustworthy machine learning › robustness › adversarial robustness
adversarial training |
0.6 | 1 | 2022 | Rethinking and Improving Robustness of Convolutional Neural Networks: a Shapley Value-based Approach in Frequency Domain · NeurIPS 2022 |
Machine learning › Graph learning › graph matching
deep graph matching |
0.6 | 1 | 2022 | Appearance and Structure Aware Robust Deep Visual Graph Matching: Attack, Defense and Beyond · CVPR 2022 |
Knowledge, reasoning and agents › Knowledge representation and reasoning › normative reasoning
moral reasoning |
0.3 | 1 | 2026 | Between a Rock and a Hard Place: The Tension Between Ethical Reasoning and Safety Alignment in LLMs · ACL (1) 2026 |
Computer vision › 3D vision › feature matching › local feature matching
keypoint matching |
0.2 | 1 | 2024 | Certified Robustness on Visual Graph Matching via Searching Optimal Smoothing Range · KDD 2024 |
Computer vision › Image recognition and object detection
image classification |
0.2 | 1 | 2022 | Rethinking and Improving Robustness of Convolutional Neural Networks: a Shapley Value-based Approach in Frequency Domain · NeurIPS 2022 |
Methods — techniques the papers use, named apart from their topics
multi-turn red-teaming · 2.0LoRA · 2.0adversarial training · 1.7data augmentation · 1.1invariant causal learning · 1.1causal graph · 1.1fine-tuning · 0.9actor-network theory · 0.9randomized smoothing · 0.8adversarial attack · 0.7locality attack · 0.6frequency-domain analysis · 0.6appearance aware regularizer · 0.6
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Between a Rock and a Hard Place: The Tension Between Ethical Reasoning and Safety Alignment in LLMsabstractWarning: This paper contains potentially offensive and harmful text.Large Language Model safety alignment predominantly operates on a binary assumption that requests are either safe or unsafe.This classification proves insufficient when models encounter ethical dilemmas, where the capacity to reason through moral trade-offs creates a distinct attack surface.We formalize this vulnerability through TRIAL, a multi-turn red-teaming methodology that embeds harmful requests within ethical framings.TRIAL achieves high attack success rates across most tested models by systematically exploiting the model's ethical reasoning capabilities to frame harmful actions as morally necessary compromises.Building on these insights, we introduce ERR (Ethical Reasoning Robustness), a defense framework that distinguishes between instrumental responses that enable harmful outcomes and explanatory responses that analyze ethical frameworks without endorsing harmful acts.ERR employs a Layer-Stratified Harm-Gated LoRA architecture, achieving robust defense against reasoning-based attacks while preserving model utility. Shei Pern Chua, Zhen Leng Thai, Kai Jun Teh, Qibing Ren |
ACL (1) | 5 |
| 2025 | LLMs know their vulnerabilities: Uncover Safety Gaps through Natural Distribution ShiftsabstractSafety concerns in large language models (LLMs) have gained significant attention due to their exposure to potentially harmful data during pre-training. In this paper, we identify a new safety vulnerability in LLMs: their susceptibility to natural distribution shifts between attack prompts and original toxic prompts, where seemingly benign prompts, semantically related to harmful content, can bypass safety mechanisms. To explore this issue, we introduce a novel attack method, ActorBreaker, which identifies actors related to toxic prompts within pre-training distribution to craft multi-turn prompts that gradually lead LLMs to reveal unsafe content. ActorBreaker is grounded in Latour’s actor-network theory, encompassing both human and non-human actors to capture a broader range of vulnerabilities. Our experimental results demonstrate that ActorBreaker outperforms existing attack methods in terms of diversity, effectiveness, and efficiency across aligned LLMs. To address this vulnerability, we propose expanding safety training to cover a broader semantic space of toxic content. We thus construct a multi-turn safety dataset using ActorBreaker. Fine-tuning models on our dataset shows significant improvements in robustness, though with some trade-offs in utility. Code is available at https://github.com/AI45Lab/ActorAttack. Qibing Ren, Hao Li 0069, Dongrui Liu, Zhanxu Xie, Xiaoya Lu, Yu Qiao 0001, Lei Sha, Junchi Yan, Lizhuang Ma |
ACL (1) | 1 |
| 2024 | Certified Robustness on Visual Graph Matching via Searching Optimal Smoothing RangeabstractDeep visual graph matching (GM) is a challenging combinatorial task that involves finding a permutation matrix that indicates the correspondence between keypoints from a pair of images. Like many learning systems, empirical studies have shown that visual GM is susceptible to adversarial attacks, with reliability issues in downstream applications. To the best of our knowledge, certifying robustness for deep visual GM remains an open challenge with two main difficulties: how to handle the paired inputs together with the heavily non-linear permutation output space (especially at large scale), and how to balance the trade-off between certified robustness and matching performance. Huaqing Shao, Lanjun Wang, Qibing Ren, Junchi Yan |
KDD | 4 |
| 2023 | ROCO: A General Framework for Evaluating Robustness of Combinatorial Optimization Solvers on Graphs
Han Lu 0004, Zenan Li, Runzhong Wang, Qibing Ren, Xijun Li, Mingxuan Yuan, Xiaokang Yang 0001, Junchi Yan |
ICLR | 4 |
| 2022 | Appearance and Structure Aware Robust Deep Visual Graph Matching: Attack, Defense and BeyondabstractDespite the recent breakthrough of high accuracy deep graph matching (GM) over visual images, the robustness of deep GM models is rarely studied which yet has been revealed an important issue in modern deep nets, ranging from image recognition to graph learning tasks. We first show that an adversarial attack on keypoint localities and the hidden graphs can cause significant accuracy drop to deep GM models. Accordingly, we propose our defense strategy, namely Appearance and Structure Aware Robust Graph Matching (ASAR-GM). Specifically, orthogonal to de facto adversarial training (AT), we devise the Appearance Aware Regularizer (AAR) on those appearance-similar keypoints between graphs that are likely to confuse. Experimental results show that our ASAR-GM achieves better robustness compared to AT. Moreover, our locality attack can serve as a data augmentation technique, which boosts the state-of-the-art GM models even on the clean test dataset. Code is available at https://github.com/Thinklab-SJTU/RobustMatch. Qibing Ren, Qingquan Bao, Runzhong Wang, Junchi Yan |
CVPR | 1 |
| 2022 | DICE: Domain-attack Invariant Causal Learning for Improved Data Privacy Protection and Adversarial RobustnessabstractThe adversarial attack reveals the vulnerability of deep models by incurring test domain shift, while delusive attack relieves the privacy concern about personal data by injecting malicious noise into the training domain to make data unexploitable. However, beyond their successful applications, the two attacks can be easily defended by adversarial training (AT). While AT is not the panacea, it suffers from poor generalization for robustness. For the limitations of attack and defense, we argue that to fit data well, DNNs can learn the spurious relations between inputs and outputs, which are consequently utilized by the attack and defense and degrade their effectiveness, and DNNs can not easily capture the causal relations like humans to make robust decisions under attacks. In this paper, to better understand and improve attack and defense, we first take a bottom-up perspective to describe the correlations between latent factors and observed data, then analyze the effect of domain shift on DNNs induced by attack and finally develop our causal graph, namely Domain-attack Invariant Causal Model (DICM). Based on DICM, we propose a coherent causal invariant principle, which guides our algorithm design to infer the human-like causal relations. We call our algorithm Domain-attack Invariant Causal Learning (DICE) and the experimental results on two attacks and one defense task verify its effectiveness. Qibing Ren, Yiting Chen 0003, Yichuan Mo, Qitian Wu, Junchi Yan |
KDD | 1 |
| 2022 | Rethinking and Improving Robustness of Convolutional Neural Networks: a Shapley Value-based Approach in Frequency DomainabstractThe existence of adversarial examples poses concerns for the robustness of convolutional neural networks (CNN), for which a popular hypothesis is about the frequency bias phenomenon: CNNs rely more on high-frequency components (HFC) for classification than humans, which causes the brittleness of CNNs. However, most previous works manually select and roughly divide the image frequency spectrum and conduct qualitative analysis. In this work, we introduce Shapley value, a metric of cooperative game theory, into the frequency domain and propose to quantify the positive (negative) impact of every frequency component of data on CNNs. Based on the Shapley value, we quantify the impact in a fine-grained way and show intriguing instance disparity. Statistically, we investigate adversarial training(AT) and the adversarial attack in the frequency domain. The observations motivate us to perform an in-depth analysis and lead to multiple novel hypotheses about i) the cause of adversarial robustness of the AT model; ii) the fairness problem of AT between different classes in the same dataset; iii) the attack bias on different frequency components. Finally, we propose a Shapley-value guided data augmentation technique for improving the robustness. Experimental results on image classification benchmarks show its effectiveness. Yiting Chen 0003, Qibing Ren, Junchi Yan |
NeurIPS | 2 |