EDBT 2026 Demo / reviewers in the wild / expert
Ziyi Yin 0003
dblp:358/6428
· DBLP profile ↗
10ranked-venue papers
3as first author
10since 2021 · last 2026
0009-0002-3502-3205ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 9 · 3 first-author · 9 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 first-author · 2 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Artificial intelligence
9 papers |
Language models and text generation · 38% Trustworthy machine learning · 22% Efficient and distributed learning · 17% | |
| Interdisciplinary, comprehensive, and emerging computing
4 papers |
Medical and health informatics · 100% | |
| Network and information security
3 papers |
Security and privacy of machine learning · 100% |
Topics — the 26 heaviest of 28, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Machine learning › Trustworthy machine learning › robustness
adversarial robustness |
1.3 | 2 | 2023 | UniT: A Unified Look at Certified Robust Training against Text Adversarial Perturbation · NeurIPS 2023 VLATTACK: Multimodal Adversarial Attacks on Vision-Language Tasks via Pre-trained Models · NeurIPS 2023 |
Natural language and speech › Language models and text generation
knowledge editing |
1.0 | 1 | 2026 | Can Factual Opinions Be Edited (Manipulated) in Large Language Models? · ACL (1) 2026 |
Natural language and speech › Language models and text generation
LLM agents |
1.0 | 1 | 2026 | ICDAGENT: Empowering Agentic Large Language Models for Explainable Medical Coding · ACL (1) 2026 |
Medical and health informatics › clinical informatics
clinical coding |
1.0 | 1 | 2026 | ICDAGENT: Empowering Agentic Large Language Models for Explainable Medical Coding · ACL (1) 2026 |
Machine learning › Efficient and distributed learning › federated learning › federated learning systems
cross-silo federated learning |
0.9 | 1 | 2025 | Asymmetrical Reciprocity-based Federated Learning for Resolving Disparities in Medical Diagnosis · KDD (1) 2025 |
Machine learning › Efficient and distributed learning
federated learning |
0.9 | 1 | 2025 | Asymmetrical Reciprocity-based Federated Learning for Resolving Disparities in Medical Diagnosis · KDD (1) 2025 |
Medical and health informatics
clinical diagnosis |
0.9 | 1 | 2025 | Asymmetrical Reciprocity-based Federated Learning for Resolving Disparities in Medical Diagnosis · KDD (1) 2025 |
Natural language and speech › Language models and text generation
alignment |
0.8 | 1 | 2024 | Personalized Steering of Large Language Models: Versatile Steering Vectors Through Bi-directional Preference Optimization · NeurIPS 2024 |
Natural language and speech › Language models and text generation
preference optimization |
0.8 | 1 | 2024 | Personalized Steering of Large Language Models: Versatile Steering Vectors Through Bi-directional Preference Optimization · NeurIPS 2024 |
Natural language and speech › Language models and text generation
steering vectors |
0.8 | 1 | 2024 | Personalized Steering of Large Language Models: Versatile Steering Vectors Through Bi-directional Preference Optimization · NeurIPS 2024 |
Medical and health informatics
electronic health records |
0.8 | 1 | 2024 | Recent Advances in Predictive Modeling with Electronic Health Records · IJCAI 2024 |
Security and privacy of machine learning › adversarial attack › multimodal adversarial attack
vision-language model attack |
0.8 | 1 | 2024 | VQAttack: Transferable Adversarial Attacks on Visual Question Answering via Pre-trained Models · AAAI 2024 |
Machine learning › Trustworthy machine learning › robustness
certified robustness |
0.7 | 1 | 2023 | UniT: A Unified Look at Certified Robust Training against Text Adversarial Perturbation · NeurIPS 2023 |
Machine learning › Representation and self-supervised learning › pre-training
hierarchical pretraining |
0.7 | 1 | 2023 | Hierarchical Pretraining on Multimodal Electronic Health Records · EMNLP 2023 |
Machine learning › Representation and self-supervised learning › pre-training
multimodal pretraining |
0.7 | 1 | 2023 | Hierarchical Pretraining on Multimodal Electronic Health Records · EMNLP 2023 |
Machine learning › Trustworthy machine learning › adversarial machine learning › adversarial natural language processing
textual adversarial examples |
0.7 | 1 | 2023 | UniT: A Unified Look at Certified Robust Training against Text Adversarial Perturbation · NeurIPS 2023 |
Computer vision › Vision and language › vision-language model
vision-language pre-trained model |
0.7 | 1 | 2023 | VLATTACK: Multimodal Adversarial Attacks on Vision-Language Tasks via Pre-trained Models · NeurIPS 2023 |
Medical and health informatics › electronic health records
electronic health record analysis |
0.7 | 1 | 2023 | Hierarchical Pretraining on Multimodal Electronic Health Records · EMNLP 2023 |
Security and privacy of machine learning
adversarial attack |
0.7 | 1 | 2023 | VLATTACK: Multimodal Adversarial Attacks on Vision-Language Tasks via Pre-trained Models · NeurIPS 2023 |
Security and privacy of machine learning › adversarial attack
multimodal adversarial attack |
0.7 | 1 | 2023 | VLATTACK: Multimodal Adversarial Attacks on Vision-Language Tasks via Pre-trained Models · NeurIPS 2023 |
Machine learning › Efficient and distributed learning › model compression
knowledge distillation |
0.3 | 1 | 2025 | Asymmetrical Reciprocity-based Federated Learning for Resolving Disparities in Medical Diagnosis · KDD (1) 2025 |
Natural language and speech › Language models and text generation
hallucination mitigation |
0.2 | 1 | 2024 | Personalized Steering of Large Language Models: Versatile Steering Vectors Through Bi-directional Preference Optimization · NeurIPS 2024 |
Machine learning › Deep learning architectures and training
sequence modeling |
0.2 | 1 | 2024 | Recent Advances in Predictive Modeling with Electronic Health Records · IJCAI 2024 |
Computer vision › Vision and language
visual question answering |
0.2 | 1 | 2024 | VQAttack: Transferable Adversarial Attacks on Visual Question Answering via Pre-trained Models · AAAI 2024 |
Natural language and speech › Information extraction and text analysis
text classification |
0.2 | 1 | 2023 | UniT: A Unified Look at Certified Robust Training against Text Adversarial Perturbation · NeurIPS 2023 |
Security and privacy of machine learning › adversarial attack
black-box attack |
0.2 | 1 | 2023 | VLATTACK: Multimodal Adversarial Attacks on Vision-Language Tasks via Pre-trained Models · NeurIPS 2023 |
Methods — techniques the papers use, named apart from their topics
large language model · 3.5self-generated evidence alignment · 2.0reinforcement learning · 2.0chain-of-thought reasoning · 2.0benchmark evaluation · 2.0knowledge distillation · 1.7foundation model knowledge transfer · 1.7synonym-based substitution · 1.5cross-modal joint attack · 1.5activation steering · 0.8transfer attack · 0.7pre-training · 0.7iterative cross-search attack · 0.7block-wise similarity attack · 0.7
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Can Factual Opinions Be Edited (Manipulated) in Large Language Models?abstractLarge Language Models (LLMs) are increasingly integrated into various domains, making knowledge editing techniques crucial yet potentially hazardous.Current editing methods primarily target atomic facts, overlooking the significant risks associated with manipulating "factual opinions", e.g., documented stances of public figures on societal issues.Such manipulation could reshape public images, influence elections, and alter societal views.To systematically assess this threat, we introduce the Factual Opinion Editing with Evidence (FOE) benchmark, which encompasses 261 public figures, 19 issue categories, and 2,178 complete opinion records.Our evaluations demonstrate that current editing techniques struggle significantly with factual opinions, often achieving only superficial changes while failing to preserve consistency between the edited opinion and the supporting evidence generated by the model.To address this limitation, we further propose a simple yet effective Self-Generated Evidence-Aligned method that achieves opinion-evidence alignment without relying on explicit instructions.Together, our benchmark and method provide a foundation for understanding the emerging security implications of factual opinion editing in LLMs. Yuanpu Cao, Ziyi Yin 0003, Fenglong Ma |
ACL (1) | 2 |
| 2026 | ICDAGENT: Empowering Agentic Large Language Models for Explainable Medical CodingabstractThe explainable medical coding task aims to automatically assign International Classification of Diseases (ICD) codes to clinical notes while providing explicit justifications for each assignment.Recent approaches employ large language models (LLMs) to generate such explanations.However, their performance remains limited due to a lack of understanding of the clinical meanings of ICD codes.Additionally, the vast ICD code space further complicates the task of accurate prediction.To address these challenges, we propose the ICDAGENT framework, which consists of two collaborative LLM agents: a coding agent and a critical agent.The coding agent extracts ICD codes and generates preliminary rationales, while the critical agent performs fine-grained chain-of-thought reasoning to verify and refine them.Furthermore, the critical agent is trained with a rationaleaware reward, combined with reinforcement learning, enabling it to distinguish between correct and incorrect reasoning and ensure explanation accuracy.Experiments across multiple ICD coding standards and datasets demonstrate that ICDAGENT achieves effective ICD coding with accurate and trustworthy explanations.1 Ziyi Yin 0003, Yuanpu Cao, Ting Wang 0006, Fenglong Ma |
ACL (1) | 1 |
| 2025 | Asymmetrical Reciprocity-based Federated Learning for Resolving Disparities in Medical DiagnosisabstractGeographic health disparities pose a pressing global challenge, particularly in underserved regions of low- and middle-income nations. Addressing this issue requires a collaborative approach to enhance healthcare quality, leveraging support from medically more developed areas. Federated learning emerges as a promising tool for this purpose. However, the scarcity of medical data and limited computation resources in underserved regions make collaborative training of powerful machine learning models challenging. Furthermore, there exists an asymmetrical reciprocity between underserved and developed regions. To overcome these challenges, we propose a novel cross-silo federated learning framework, named FedHelp, aimed at alleviating geographic health disparities and fortifying the diagnostic capabilities of underserved regions. Specifically, FedHelp leverages foundational model knowledge via one-time API access to guide the learning process of underserved small clients, addressing the challenge of insufficient data. Additionally, we introduce a novel asymmetric dual knowledge distillation module to manage the issue of asymmetric reciprocity, facilitating the exchange of necessary knowledge between developed large clients and underserved small clients. We validate the effectiveness and utility of FedHelp through extensive experiments on both medical image classification and segmentation tasks. The experimental results demonstrate significant performance improvement compared to state-of-the-art baselines, particularly benefiting clients in underserved regions. Jiaqi Wang 0002, Ziyi Yin 0003, Quanzeng You, Lingjuan Lyu, Fenglong Ma |
KDD (1) | 2 |
| 2024 | VQAttack: Transferable Adversarial Attacks on Visual Question Answering via Pre-trained ModelsabstractVisual Question Answering (VQA) is a fundamental task in computer vision and natural language process fields. Although the “pre-training & finetuning” learning paradigm significantly improves the VQA performance, the adversarial robustness of such a learning paradigm has not been explored. In this paper, we delve into a new problem: using a pre-trained multimodal source model to create adversarial image-text pairs and then transferring them to attack the target VQA models. Correspondingly, we propose a novel VQATTACK model, which can iteratively generate both im- age and text perturbations with the designed modules: the large language model (LLM)-enhanced image attack and the cross-modal joint attack module. At each iteration, the LLM-enhanced image attack module first optimizes the latent representation-based loss to generate feature-level image perturbations. Then it incorporates an LLM to further enhance the image perturbations by optimizing the designed masked answer anti-recovery loss. The cross-modal joint attack module will be triggered at a specific iteration, which updates the image and text perturbations sequentially. Notably, the text perturbation updates are based on both the learned gradients in the word embedding space and word synonym-based substitution. Experimental results on two VQA datasets with five validated models demonstrate the effectiveness of the proposed VQATTACK in the transferable attack setting, compared with state-of-the-art baselines. This work reveals a significant blind spot in the “pre-training & fine-tuning” paradigm on VQA tasks. The source code can be found in the link https://github.com/ericyinyzy/VQAttack. Ziyi Yin 0003, Muchao Ye, Tianrong Zhang, Jiaqi Wang 0002, Han Liu 0008, Ting Wang 0006, Fenglong Ma |
AAAI | 1 |
| 2024 | Recent Advances in Predictive Modeling with Electronic Health Records
Jiaqi Wang 0002, Junyu Luo 0001, Muchao Ye, Xiaochen Wang 0002, Yuan Zhong 0002, Aofei Chang, Guanjie Huang, Ziyi Yin 0003, Cao Xiao, Jimeng Sun 0001, Fenglong Ma |
IJCAI | 8 |
| 2024 | Personalized Steering of Large Language Models: Versatile Steering Vectors Through Bi-directional Preference OptimizationabstractResearchers have been studying approaches to steer the behavior of Large Language Models (LLMs) and build personalized LLMs tailored for various applications. While fine-tuning seems to be a direct solution, it requires substantial computational resources and may significantly affect the utility of the original LLM.
Recent endeavors have introduced more lightweight strategies, focusing on extracting ``steering vectors'' to guide the model's output toward desired behaviors by adjusting activations within specific layers of the LLM's transformer architecture. However, such steering vectors are directly extracted from the activations of human preference data and thus often lead to suboptimal results and occasional failures, especially in alignment-related scenarios.
In this work, we propose an innovative approach that could produce more effective steering vectors through bi-directional preference optimization.
Our method is designed to allow steering vectors to directly influence the generation probability of contrastive human preference data pairs, thereby offering a more precise representation of the target behavior. By carefully adjusting the direction and magnitude of the steering vector, we enabled personalized control over the desired behavior across a spectrum of intensities.
Extensive experimentation across various open-ended generation tasks, particularly focusing on steering AI personas, has validated the efficacy of our approach.
Moreover, we comprehensively investigate critical alignment-concerning scenarios, such as managing truthfulness, mitigating hallucination, and addressing jailbreaking attacks alongside their respective defenses. Remarkably, our method can still demonstrate outstanding steering effectiveness across these scenarios. Furthermore, we showcase the transferability of our steering vectors across different models/LoRAs and highlight the synergistic benefits of applying multiple vectors simultaneously. These findings significantly broaden the practicality and versatility of our proposed method. Yuanpu Cao, Tianrong Zhang, Bochuan Cao, Ziyi Yin 0003, Lu Lin 0001, Fenglong Ma |
NeurIPS | 4 |
| 2024 | MedDiffusion: Boosting Health Risk Prediction via Diffusion-based Data AugmentationabstractHealth risk prediction aims to forecast the potential health risks that patients may face using their historical Electronic Health Records (EHR). Although several effective models have developed, data insufficiency is a key issue undermining their effectiveness. Various data generation and augmentation methods have been introduced to mitigate this issue by expanding the size of the training data set through learning underlying data distributions. However, the performance of these methods is often limited due to their task-unrelated design. To address these shortcomings, this paper introduces a novel, end-to-end diffusion-based risk prediction model, named MedDiffusion. It enhances risk prediction performance by creating synthetic patient data during training to enlarge sample space. Furthermore, MedDiffusion discerns hidden relationships between patient visits using a step-wise attention mechanism, enabling the model to automatically retain the most vital information for generating high-quality data. Experimental evaluation on four real-world medical datasets demonstrates that MedDiffusion outperforms 14 cutting-edge baselines in terms of PR-AUC, F1, and Cohen's Kappa. We also conduct ablation studies and benchmark our model against GAN-based alternatives to further validate the rationality and adaptability of our model design. Additionally, we analyze generated data to offer fresh insights into the model's interpretability. The source code is available via https://shorturl.at/aerT0. Yuan Zhong 0002, Suhan Cui, Jiaqi Wang 0002, Xiaochen Wang 0002, Ziyi Yin 0003, Yaqing Wang 0001, Houping Xiao, Mengdi Huai, Ting Wang 0006, Fenglong Ma |
SDM | 5 |
| 2023 | Hierarchical Pretraining on Multimodal Electronic Health RecordsabstractPretraining has proven to be a powerful technique in natural language processing (NLP), exhibiting remarkable success in various NLP downstream tasks. However, in the medical domain, existing pretrained models on electronic health records (EHR) fail to capture the hierarchical nature of EHR data, limiting their generalization capability across diverse downstream tasks using a single pretrained model. To tackle this challenge, this paper introduces a novel, general, and unified pretraining framework called MedHMP, specifically designed for hierarchically multimodal EHR data. The effectiveness of the proposed MedHMP is demonstrated through experimental results on eight downstream tasks spanning three levels. Comparisons against eighteen baselines further highlight the efficacy of our approach. Xiaochen Wang 0002, Junyu Luo 0001, Jiaqi Wang 0002, Ziyi Yin 0003, Suhan Cui, Yuan Zhong 0002, Yaqing Wang 0001, Fenglong Ma |
EMNLP | 4 |
| 2023 | VLATTACK: Multimodal Adversarial Attacks on Vision-Language Tasks via Pre-trained ModelsabstractVision-Language (VL) pre-trained models have shown their superiority on many multimodal tasks. However, the adversarial robustness of such models has not been fully explored. Existing approaches mainly focus on exploring the adversarial robustness under the white-box setting, which is unrealistic. In this paper, we aim to investigate a new yet practical task to craft image and text perturbations using pre-trained VL models to attack black-box fine-tuned models on different downstream tasks. Towards this end, we propose VLATTACK to generate adversarial samples by fusing perturbations of images and texts from both single-modal and multi-modal levels. At the single-modal level, we propose a new block-wise similarity attack (BSA) strategy to learn image perturbations for disrupting universal representations. Besides, we adopt an existing text attack strategy to generate text perturbations independent of the image-modal attack. At the multi-modal level, we design a novel iterative cross-search attack (ICSA) method to update adversarial image-text pairs periodically, starting with the outputs from the single-modal level. We conduct extensive experiments to attack three widely-used VL pretrained models for six tasks on eight datasets. Experimental results show that the proposed VLATTACK framework achieves the highest attack success rates on all tasks compared with state-of-the-art baselines, which reveals a significant blind spot in the deployment of pre-trained VL models. Ziyi Yin 0003, Muchao Ye, Tianrong Zhang, Tianyu Du, Jinguo Zhu, Han Liu 0008, Ting Wang 0006, Fenglong Ma |
NeurIPS | 1 |
| 2023 | UniT: A Unified Look at Certified Robust Training against Text Adversarial PerturbationabstractRecent years have witnessed a surge of certified robust training pipelines against text adversarial perturbation constructed by synonym substitutions. Given a base model, existing pipelines provide prediction certificates either in the discrete word space or the continuous latent space. However, they are isolated from each other with a structural gap. We observe that existing training frameworks need unification to provide stronger certified robustness. Additionally, they mainly focus on building the certification process but neglect to improve the robustness of the base model. To mitigate the aforementioned limitations, we propose a unified framework named UniT that enables us to train flexibly in either fashion by working in the word embedding space. It can provide a stronger robustness guarantee obtained directly from the word embedding space without extra modules. In addition, we introduce the decoupled regularization (DR) loss to improve the robustness of the base model, which includes two separate robustness regularization terms for the feature extraction and classifier modules. Experimental results on widely used text classification datasets further demonstrate the effectiveness of the designed unified framework and the proposed DR loss for improving the certified robust accuracy. Muchao Ye, Ziyi Yin 0003, Tianrong Zhang, Tianyu Du, Ting Wang 0006, Fenglong Ma |
NeurIPS | 2 |