Demonstration venue · read-only. Every page can be browsed; the buttons that would change it are switched off. Create an account to run TaxoReview on your own data.

Ziyi Yin 0003

dblp:358/6428 · DBLP profile ↗
← Back
10ranked-venue papers
3as first author
10since 2021 · last 2026
0009-0002-3502-3205ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 9 · 3 first-author · 9 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 first-author · 2 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Artificial intelligence
9 papers
Language models and text generation · 38% Trustworthy machine learning · 22% Efficient and distributed learning · 17%
Interdisciplinary, comprehensive, and emerging computing
4 papers
Medical and health informatics · 100%
Network and information security
3 papers
Security and privacy of machine learning · 100%

Topics — the 26 heaviest of 28, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Machine learning › Trustworthy machine learning › robustness
adversarial robustness
1.322023
UniT: A Unified Look at Certified Robust Training against Text Adversarial Perturbation · NeurIPS 2023
VLATTACK: Multimodal Adversarial Attacks on Vision-Language Tasks via Pre-trained Models · NeurIPS 2023
Natural language and speech › Language models and text generation
knowledge editing
1.012026
Can Factual Opinions Be Edited (Manipulated) in Large Language Models? · ACL (1) 2026
Natural language and speech › Language models and text generation
LLM agents
1.012026
ICDAGENT: Empowering Agentic Large Language Models for Explainable Medical Coding · ACL (1) 2026
Medical and health informatics › clinical informatics
clinical coding
1.012026
ICDAGENT: Empowering Agentic Large Language Models for Explainable Medical Coding · ACL (1) 2026
Machine learning › Efficient and distributed learning › federated learning › federated learning systems
cross-silo federated learning
0.912025
Asymmetrical Reciprocity-based Federated Learning for Resolving Disparities in Medical Diagnosis · KDD (1) 2025
Machine learning › Efficient and distributed learning
federated learning
0.912025
Asymmetrical Reciprocity-based Federated Learning for Resolving Disparities in Medical Diagnosis · KDD (1) 2025
Medical and health informatics
clinical diagnosis
0.912025
Asymmetrical Reciprocity-based Federated Learning for Resolving Disparities in Medical Diagnosis · KDD (1) 2025
Natural language and speech › Language models and text generation
alignment
0.812024
Personalized Steering of Large Language Models: Versatile Steering Vectors Through Bi-directional Preference Optimization · NeurIPS 2024
Natural language and speech › Language models and text generation
preference optimization
0.812024
Personalized Steering of Large Language Models: Versatile Steering Vectors Through Bi-directional Preference Optimization · NeurIPS 2024
Natural language and speech › Language models and text generation
steering vectors
0.812024
Personalized Steering of Large Language Models: Versatile Steering Vectors Through Bi-directional Preference Optimization · NeurIPS 2024
Medical and health informatics
electronic health records
0.812024
Recent Advances in Predictive Modeling with Electronic Health Records · IJCAI 2024
Security and privacy of machine learning › adversarial attack › multimodal adversarial attack
vision-language model attack
0.812024
VQAttack: Transferable Adversarial Attacks on Visual Question Answering via Pre-trained Models · AAAI 2024
Machine learning › Trustworthy machine learning › robustness
certified robustness
0.712023
UniT: A Unified Look at Certified Robust Training against Text Adversarial Perturbation · NeurIPS 2023
Machine learning › Representation and self-supervised learning › pre-training
hierarchical pretraining
0.712023
Hierarchical Pretraining on Multimodal Electronic Health Records · EMNLP 2023
Machine learning › Representation and self-supervised learning › pre-training
multimodal pretraining
0.712023
Hierarchical Pretraining on Multimodal Electronic Health Records · EMNLP 2023
Machine learning › Trustworthy machine learning › adversarial machine learning › adversarial natural language processing
textual adversarial examples
0.712023
UniT: A Unified Look at Certified Robust Training against Text Adversarial Perturbation · NeurIPS 2023
Computer vision › Vision and language › vision-language model
vision-language pre-trained model
0.712023
VLATTACK: Multimodal Adversarial Attacks on Vision-Language Tasks via Pre-trained Models · NeurIPS 2023
Medical and health informatics › electronic health records
electronic health record analysis
0.712023
Hierarchical Pretraining on Multimodal Electronic Health Records · EMNLP 2023
Security and privacy of machine learning
adversarial attack
0.712023
VLATTACK: Multimodal Adversarial Attacks on Vision-Language Tasks via Pre-trained Models · NeurIPS 2023
Security and privacy of machine learning › adversarial attack
multimodal adversarial attack
0.712023
VLATTACK: Multimodal Adversarial Attacks on Vision-Language Tasks via Pre-trained Models · NeurIPS 2023
Machine learning › Efficient and distributed learning › model compression
knowledge distillation
0.312025
Asymmetrical Reciprocity-based Federated Learning for Resolving Disparities in Medical Diagnosis · KDD (1) 2025
Natural language and speech › Language models and text generation
hallucination mitigation
0.212024
Personalized Steering of Large Language Models: Versatile Steering Vectors Through Bi-directional Preference Optimization · NeurIPS 2024
Machine learning › Deep learning architectures and training
sequence modeling
0.212024
Recent Advances in Predictive Modeling with Electronic Health Records · IJCAI 2024
Computer vision › Vision and language
visual question answering
0.212024
VQAttack: Transferable Adversarial Attacks on Visual Question Answering via Pre-trained Models · AAAI 2024
Natural language and speech › Information extraction and text analysis
text classification
0.212023
UniT: A Unified Look at Certified Robust Training against Text Adversarial Perturbation · NeurIPS 2023
Security and privacy of machine learning › adversarial attack
black-box attack
0.212023
VLATTACK: Multimodal Adversarial Attacks on Vision-Language Tasks via Pre-trained Models · NeurIPS 2023

Methods — techniques the papers use, named apart from their topics

large language model · 3.5self-generated evidence alignment · 2.0reinforcement learning · 2.0chain-of-thought reasoning · 2.0benchmark evaluation · 2.0knowledge distillation · 1.7foundation model knowledge transfer · 1.7synonym-based substitution · 1.5cross-modal joint attack · 1.5activation steering · 0.8transfer attack · 0.7pre-training · 0.7iterative cross-search attack · 0.7block-wise similarity attack · 0.7
YearPublicationVenuePosition
2026 Can Factual Opinions Be Edited (Manipulated) in Large Language Models?
abstract
Large Language Models (LLMs) are increasingly integrated into various domains, making knowledge editing techniques crucial yet potentially hazardous.Current editing methods primarily target atomic facts, overlooking the significant risks associated with manipulating "factual opinions", e.g., documented stances of public figures on societal issues.Such manipulation could reshape public images, influence elections, and alter societal views.To systematically assess this threat, we introduce the Factual Opinion Editing with Evidence (FOE) benchmark, which encompasses 261 public figures, 19 issue categories, and 2,178 complete opinion records.Our evaluations demonstrate that current editing techniques struggle significantly with factual opinions, often achieving only superficial changes while failing to preserve consistency between the edited opinion and the supporting evidence generated by the model.To address this limitation, we further propose a simple yet effective Self-Generated Evidence-Aligned method that achieves opinion-evidence alignment without relying on explicit instructions.Together, our benchmark and method provide a foundation for understanding the emerging security implications of factual opinion editing in LLMs.
Yuanpu Cao, Ziyi Yin 0003, Fenglong Ma
ACL (1)2
2026 ICDAGENT: Empowering Agentic Large Language Models for Explainable Medical Coding
abstract
The explainable medical coding task aims to automatically assign International Classification of Diseases (ICD) codes to clinical notes while providing explicit justifications for each assignment.Recent approaches employ large language models (LLMs) to generate such explanations.However, their performance remains limited due to a lack of understanding of the clinical meanings of ICD codes.Additionally, the vast ICD code space further complicates the task of accurate prediction.To address these challenges, we propose the ICDAGENT framework, which consists of two collaborative LLM agents: a coding agent and a critical agent.The coding agent extracts ICD codes and generates preliminary rationales, while the critical agent performs fine-grained chain-of-thought reasoning to verify and refine them.Furthermore, the critical agent is trained with a rationaleaware reward, combined with reinforcement learning, enabling it to distinguish between correct and incorrect reasoning and ensure explanation accuracy.Experiments across multiple ICD coding standards and datasets demonstrate that ICDAGENT achieves effective ICD coding with accurate and trustworthy explanations.1
Ziyi Yin 0003, Yuanpu Cao, Ting Wang 0006, Fenglong Ma
ACL (1)1
2025 Asymmetrical Reciprocity-based Federated Learning for Resolving Disparities in Medical Diagnosis
abstract
Geographic health disparities pose a pressing global challenge, particularly in underserved regions of low- and middle-income nations. Addressing this issue requires a collaborative approach to enhance healthcare quality, leveraging support from medically more developed areas. Federated learning emerges as a promising tool for this purpose. However, the scarcity of medical data and limited computation resources in underserved regions make collaborative training of powerful machine learning models challenging. Furthermore, there exists an asymmetrical reciprocity between underserved and developed regions. To overcome these challenges, we propose a novel cross-silo federated learning framework, named FedHelp, aimed at alleviating geographic health disparities and fortifying the diagnostic capabilities of underserved regions. Specifically, FedHelp leverages foundational model knowledge via one-time API access to guide the learning process of underserved small clients, addressing the challenge of insufficient data. Additionally, we introduce a novel asymmetric dual knowledge distillation module to manage the issue of asymmetric reciprocity, facilitating the exchange of necessary knowledge between developed large clients and underserved small clients. We validate the effectiveness and utility of FedHelp through extensive experiments on both medical image classification and segmentation tasks. The experimental results demonstrate significant performance improvement compared to state-of-the-art baselines, particularly benefiting clients in underserved regions.
Jiaqi Wang 0002, Ziyi Yin 0003, Quanzeng You, Lingjuan Lyu, Fenglong Ma
KDD (1)2
2024 VQAttack: Transferable Adversarial Attacks on Visual Question Answering via Pre-trained Models
abstract
Visual Question Answering (VQA) is a fundamental task in computer vision and natural language process fields. Although the “pre-training & finetuning” learning paradigm significantly improves the VQA performance, the adversarial robustness of such a learning paradigm has not been explored. In this paper, we delve into a new problem: using a pre-trained multimodal source model to create adversarial image-text pairs and then transferring them to attack the target VQA models. Correspondingly, we propose a novel VQATTACK model, which can iteratively generate both im- age and text perturbations with the designed modules: the large language model (LLM)-enhanced image attack and the cross-modal joint attack module. At each iteration, the LLM-enhanced image attack module first optimizes the latent representation-based loss to generate feature-level image perturbations. Then it incorporates an LLM to further enhance the image perturbations by optimizing the designed masked answer anti-recovery loss. The cross-modal joint attack module will be triggered at a specific iteration, which updates the image and text perturbations sequentially. Notably, the text perturbation updates are based on both the learned gradients in the word embedding space and word synonym-based substitution. Experimental results on two VQA datasets with five validated models demonstrate the effectiveness of the proposed VQATTACK in the transferable attack setting, compared with state-of-the-art baselines. This work reveals a significant blind spot in the “pre-training & fine-tuning” paradigm on VQA tasks. The source code can be found in the link https://github.com/ericyinyzy/VQAttack.
Ziyi Yin 0003, Muchao Ye, Tianrong Zhang, Jiaqi Wang 0002, Han Liu 0008, Ting Wang 0006, Fenglong Ma
AAAI1
2024 Recent Advances in Predictive Modeling with Electronic Health Records
Jiaqi Wang 0002, Junyu Luo 0001, Muchao Ye, Xiaochen Wang 0002, Yuan Zhong 0002, Aofei Chang, Guanjie Huang, Ziyi Yin 0003, Cao Xiao, Jimeng Sun 0001, Fenglong Ma
IJCAI8
2024 Personalized Steering of Large Language Models: Versatile Steering Vectors Through Bi-directional Preference Optimization
abstract
Researchers have been studying approaches to steer the behavior of Large Language Models (LLMs) and build personalized LLMs tailored for various applications. While fine-tuning seems to be a direct solution, it requires substantial computational resources and may significantly affect the utility of the original LLM. Recent endeavors have introduced more lightweight strategies, focusing on extracting ``steering vectors'' to guide the model's output toward desired behaviors by adjusting activations within specific layers of the LLM's transformer architecture. However, such steering vectors are directly extracted from the activations of human preference data and thus often lead to suboptimal results and occasional failures, especially in alignment-related scenarios. In this work, we propose an innovative approach that could produce more effective steering vectors through bi-directional preference optimization. Our method is designed to allow steering vectors to directly influence the generation probability of contrastive human preference data pairs, thereby offering a more precise representation of the target behavior. By carefully adjusting the direction and magnitude of the steering vector, we enabled personalized control over the desired behavior across a spectrum of intensities. Extensive experimentation across various open-ended generation tasks, particularly focusing on steering AI personas, has validated the efficacy of our approach. Moreover, we comprehensively investigate critical alignment-concerning scenarios, such as managing truthfulness, mitigating hallucination, and addressing jailbreaking attacks alongside their respective defenses. Remarkably, our method can still demonstrate outstanding steering effectiveness across these scenarios. Furthermore, we showcase the transferability of our steering vectors across different models/LoRAs and highlight the synergistic benefits of applying multiple vectors simultaneously. These findings significantly broaden the practicality and versatility of our proposed method.
Yuanpu Cao, Tianrong Zhang, Bochuan Cao, Ziyi Yin 0003, Lu Lin 0001, Fenglong Ma
NeurIPS4
2024 MedDiffusion: Boosting Health Risk Prediction via Diffusion-based Data Augmentation
abstract
Health risk prediction aims to forecast the potential health risks that patients may face using their historical Electronic Health Records (EHR). Although several effective models have developed, data insufficiency is a key issue undermining their effectiveness. Various data generation and augmentation methods have been introduced to mitigate this issue by expanding the size of the training data set through learning underlying data distributions. However, the performance of these methods is often limited due to their task-unrelated design. To address these shortcomings, this paper introduces a novel, end-to-end diffusion-based risk prediction model, named MedDiffusion. It enhances risk prediction performance by creating synthetic patient data during training to enlarge sample space. Furthermore, MedDiffusion discerns hidden relationships between patient visits using a step-wise attention mechanism, enabling the model to automatically retain the most vital information for generating high-quality data. Experimental evaluation on four real-world medical datasets demonstrates that MedDiffusion outperforms 14 cutting-edge baselines in terms of PR-AUC, F1, and Cohen's Kappa. We also conduct ablation studies and benchmark our model against GAN-based alternatives to further validate the rationality and adaptability of our model design. Additionally, we analyze generated data to offer fresh insights into the model's interpretability. The source code is available via https://shorturl.at/aerT0.
Yuan Zhong 0002, Suhan Cui, Jiaqi Wang 0002, Xiaochen Wang 0002, Ziyi Yin 0003, Yaqing Wang 0001, Houping Xiao, Mengdi Huai, Ting Wang 0006, Fenglong Ma
SDM5
2023 Hierarchical Pretraining on Multimodal Electronic Health Records
abstract
Pretraining has proven to be a powerful technique in natural language processing (NLP), exhibiting remarkable success in various NLP downstream tasks. However, in the medical domain, existing pretrained models on electronic health records (EHR) fail to capture the hierarchical nature of EHR data, limiting their generalization capability across diverse downstream tasks using a single pretrained model. To tackle this challenge, this paper introduces a novel, general, and unified pretraining framework called MedHMP, specifically designed for hierarchically multimodal EHR data. The effectiveness of the proposed MedHMP is demonstrated through experimental results on eight downstream tasks spanning three levels. Comparisons against eighteen baselines further highlight the efficacy of our approach.
Xiaochen Wang 0002, Junyu Luo 0001, Jiaqi Wang 0002, Ziyi Yin 0003, Suhan Cui, Yuan Zhong 0002, Yaqing Wang 0001, Fenglong Ma
EMNLP4
2023 VLATTACK: Multimodal Adversarial Attacks on Vision-Language Tasks via Pre-trained Models
abstract
Vision-Language (VL) pre-trained models have shown their superiority on many multimodal tasks. However, the adversarial robustness of such models has not been fully explored. Existing approaches mainly focus on exploring the adversarial robustness under the white-box setting, which is unrealistic. In this paper, we aim to investigate a new yet practical task to craft image and text perturbations using pre-trained VL models to attack black-box fine-tuned models on different downstream tasks. Towards this end, we propose VLATTACK to generate adversarial samples by fusing perturbations of images and texts from both single-modal and multi-modal levels. At the single-modal level, we propose a new block-wise similarity attack (BSA) strategy to learn image perturbations for disrupting universal representations. Besides, we adopt an existing text attack strategy to generate text perturbations independent of the image-modal attack. At the multi-modal level, we design a novel iterative cross-search attack (ICSA) method to update adversarial image-text pairs periodically, starting with the outputs from the single-modal level. We conduct extensive experiments to attack three widely-used VL pretrained models for six tasks on eight datasets. Experimental results show that the proposed VLATTACK framework achieves the highest attack success rates on all tasks compared with state-of-the-art baselines, which reveals a significant blind spot in the deployment of pre-trained VL models.
Ziyi Yin 0003, Muchao Ye, Tianrong Zhang, Tianyu Du, Jinguo Zhu, Han Liu 0008, Ting Wang 0006, Fenglong Ma
NeurIPS1
2023 UniT: A Unified Look at Certified Robust Training against Text Adversarial Perturbation
abstract
Recent years have witnessed a surge of certified robust training pipelines against text adversarial perturbation constructed by synonym substitutions. Given a base model, existing pipelines provide prediction certificates either in the discrete word space or the continuous latent space. However, they are isolated from each other with a structural gap. We observe that existing training frameworks need unification to provide stronger certified robustness. Additionally, they mainly focus on building the certification process but neglect to improve the robustness of the base model. To mitigate the aforementioned limitations, we propose a unified framework named UniT that enables us to train flexibly in either fashion by working in the word embedding space. It can provide a stronger robustness guarantee obtained directly from the word embedding space without extra modules. In addition, we introduce the decoupled regularization (DR) loss to improve the robustness of the base model, which includes two separate robustness regularization terms for the feature extraction and classifier modules. Experimental results on widely used text classification datasets further demonstrate the effectiveness of the designed unified framework and the proposed DR loss for improving the certified robust accuracy.
Muchao Ye, Ziyi Yin 0003, Tianrong Zhang, Tianyu Du, Ting Wang 0006, Fenglong Ma
NeurIPS2