Longzhu He

dblp:382/3238 · DBLP profile ↗
← Back
11ranked-venue papers
6as first author
11since 2021 · last 2026
0009-0001-7842-6605ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Databases, data management, data science and information retrieval · 6 · 5 first-author · 6 since 2021Artificial intelligence and machine learning · 5 · 2 first-author · 5 since 2021Systems, architecture and hardware · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 Learning to Edit Knowledge via Instruction-based Chain-of-Thought Prompting
abstract
Large language models (LLMs) can effectively handle outdated information through knowledge editing.However, current approaches face two key limitations: (I) Poor generalization: Most approaches rigidly inject new knowledge without ensuring that the model can use it effectively to solve practical problems.(II) Narrow scope: Current methods focus primarily on structured fact triples, overlooking the diverse unstructured forms of factual information (e.g., news, articles) prevalent in real-world contexts.To address these challenges, we propose a new paradigm: teaching LLMs to edit knowledge via Chain of Thoughts (CoTs) reasoning (CoT2Edit).We first leverage language model agents for both structured and unstructured edited data to generate CoTs, building high-quality instruction data.The model is then trained to reason over edited knowledge through supervised finetuning (SFT) and Group Relative Policy Optimization (GRPO).At inference time, we integrate Retrieval-Augmented Generation (RAG) to dynamically retrieve relevant edited facts for real-time knowledge editing.Experimental results demonstrate that our method achieves strong generalization across six diverse knowledge editing scenarios with just a single round of training on three open-source language models.The codes are available at https:// github.com/FredJDean/CoT2Edit.
Jinhu Fu, Longzhu He, Yihang Lou, Yanxiao Zhao, Li Sun 0008, Sen Su
ACL (1)3
2026 Devil's Hand: Data Poisoning Attacks to Locally Private Graph Learning Protocols
abstract
Graph neural networks (GNNs) have achieved significant success in graph representation learning and have been applied to various domains. However, many real-world graphs contain sensitive personal information, such as user profiles in social networks, raising serious privacy concerns when graph learning is performed using GNNs. To address this issue, locally private graph learning protocols have gained considerable attention. These protocols leverage the privacy advantages of local differential privacy (LDP) and the effectiveness of GNN's message-passing in calibrating noisy data, offering strict privacy guarantees for users' local data while maintaining high utility (e.g., node classification accuracy) for graph learning. Despite these advantages, such protocols may be vulnerable to data poisoning attacks, a threat that has not been considered in previous research. Identifying and addressing these threats is crucial for ensuring the robustness and security of privacy-preserving graph learning frameworks. This work introduces the first data poisoning attack targeting locally private graph learning protocols. The attacker injects fake users into the protocol, manipulates these fake users to establish links with genuine users, and sends carefully crafted data to the server, ultimately compromising the utility of private graph learning. The effectiveness of the attack is demonstrated both theoretically and empirically. In addition, several defense strategies have also been explored, but their limited effectiveness highlights the need for more robust defenses.
Longzhu He, Chaozhuo Li, Peng Tang 0002, Li Sun 0008, Sen Su, Philip S. Yu
KDD (1)1
2026 Separating Wheat from Chaff: Fine-Grained Defenses Against Poisoning in Multi-Perspective RAG
Yanxiao Zhao, Longzhu He, Li Sun 0008, Sen Su
SIGIR2
2026 The Devil Within, The Cure Without: Securing Locally Private Graph Learning under Poisoning
Longzhu He, Peng Tang 0002, Li Sun 0008, Sen Su
WWW1
2026 Toward Personalized Differentially Private Learning for Decentralized Local Graphs
Longzhu He, Peng Tang 0002, Chaozhuo Li, Jinhu Fu, Litian Zhang, Li Sun 0008, Philip S. Yu, Sen Su
IEEE Trans. Knowl. Data Eng.1
2026 Push and Pull: Defending against Retrieval Poisoning Attacks via Embedding Space Reshaping
abstract
Retrieval-Augmented Generation (RAG) improves the performance of Large Language Models (LLMs) by retrieving and integrating relevant information from external knowledge bases, which helps generate more accurate responses. However, RAG is vulnerable to retrieval poisoning attacks , where attackers can induce LLM to produce inaccurate responses by injecting malicious documents into the retrieval process. In this article, we propose ShieldRAG , a novel defense framework designed to counteract retrieval poisoning attacks by reshaping the retrieval embedding space. ShieldRAG leverages a dual-strategy effect realized via a majority-consensus mechanism: ① Push : Implicitly forces the embedding of a user query away from malicious documents by filtering out their minority signals, reducing their influence. ② Pull : Aligns the embedding of a user query closer to that of benign documents, reinforcing accurate retrieval. These strategies work synergistically to preserve retrieval integrity and enhance the quality of LLM-generated responses. Specifically, ShieldRAG operates through three key steps: Sliding Retrieval Explanation Generation , Keyword Aggregation , and Query Targeting Optimization . These three steps collectively ensure the effective integration of information from benign sources while filtering out malicious interference, thereby significantly enhancing the robustness of RAG systems against retrieval poisoning attacks. We evaluate ShieldRAG on four open-domain Question Answering (QA) datasets: Natural Questions, MS-MARCO, HotpotQA, and 2WikiMultiHopQA, using seven representative LLMs. Extensive experiments demonstrate that ShieldRAG significantly improves response accuracy while mitigating adversarial effects, showcasing strong generalization across multiple datasets and LLM architectures.
Longzhu He, Chaozhuo Li, Zheng Liu 0011, Pengpeng Zhou, Sen Su
ACM Trans. Inf. Syst.1
2025 Going Deeper into Locally Differentially Private Graph Neural Networks
abstract
Graph Neural Networks (GNNs) have demonstrated superior performance in a variety of graph mining and learning tasks. However, when node representations involve sensitive personal information or variables related to individuals, learning from graph data can raise significant privacy concerns. Although recent studies have explored local differential privacy (LDP) to address these concerns, they often introduce significant distortions to graph data, severely degrading private learning utility (e.g., node classification accuracy). In this paper, we present UPGNET, an LDP-based privacy-preserving graph learning framework that enhances utility while protecting user data privacy. Specifically, we propose a three-stage pipeline that generalizes the LDP protocols for node features, targeting privacy-sensitive scenarios. Our analysis identifies two key factors that affect the utility of privacy-preserving graph learning: feature dimension and neighborhood size. Based on the above analysis, UPGNET enhances utility by introducing two core layers: High-Order Aggregator (HOA) layer and the Node Feature Regularization (NFR) layer. Extensive experiments on real-world datasets indicate that UPGNET significantly outperforms existing methods in terms of both privacy protection and learning utility.
Longzhu He, Chaozhuo Li, Peng Tang 0002, Sen Su
ICML1
2025 An improved hierarchical neural network model with local and global feature matching for script event prediction
Pengpeng Zhou, Bin Wu 0001, Caiyong Wang, Longzhu He
Expert Syst. Appl.4
2025 Mitigating privacy risks in Retrieval-Augmented Generation via locally private entity perturbation
Longzhu He, Peng Tang 0002, Yuanhe Zhang, Pengpeng Zhou, Sen Su
Inf. Process. Manag.1
2024 Alignment-Enhanced Decoding: Defending Jailbreaks via Token-Level Adaptive Refining of Probability Distributions
abstract
Large language models are susceptible to jailbreak attacks, which can result in the generation of harmful content.While prior defenses mitigate these risks by perturbing or inspecting inputs, they ignore competing objectives, the underlying cause of alignment failures.In this paper, we propose Alignment-Enhanced Decoding (AED), a novel defense that employs adaptive decoding to address the root causes of jailbreak issues.We first define the Competitive Index to quantify alignment failures and utilize feedback from self-evaluation to compute postalignment logits.Then, AED adaptively combines Competitive Index and post-alignment logits with the original logits to obtain harmless and helpful distributions.Consequently, our method enhances safety alignment while maintaining helpfulness.We conduct experiments across five models and four common jailbreaks, with the results validating the effectiveness of our approach.Code is available at https://github.com/GIGABaozi/AED.
Zhenhong Zhou, Longzhu He, Sen Su
EMNLP3
2024 Enforcing group fairness in privacy-preserving Federated Learning
Chaomeng Chen, Zhenhong Zhou, Peng Tang 0002, Longzhu He, Sen Su
Future Gener. Comput. Syst.4