Bo Huang 0017

dblp:95/6229-17 · DBLP profile ↗
← Back
8ranked-venue papers
4as first author
7since 2021 · last 2026
0000-0002-5529-4734ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 8 · 4 first-author · 7 since 2021Graphics, computer vision, multimedia, augmented reality and games · 5 · 3 first-author · 4 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Artificial intelligence
6 papers
Efficient and distributed learning · 35% Generative modeling · 21% Language models and text generation · 20%
Network and information security
1 paper
Security and privacy of machine learning · 100%

Topics — the 17 heaviest of 17, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Machine learning › Generative modeling
diffusion model
1.922026
Diffusion Reconstruction-based Data Likelihood Estimation for Core-Set Selection · AAAI 2026
Influence-Guided Diffusion for Dataset Distillation · ICLR 2025
Machine learning › Efficient and distributed learning
data selection
1.322026
Diffusion Reconstruction-based Data Likelihood Estimation for Core-Set Selection · AAAI 2026
Influence-Guided Diffusion for Dataset Distillation · ICLR 2025
Machine learning › Trustworthy machine learning › robustness
adversarial robustness
1.222023
Boosting Accuracy and Robustness of Student Models via Adaptive Adversarial Distillation · CVPR 2023
Adversarial Defence by Diversified Simultaneous Training of Deep Ensembles · AAAI 2021
Machine learning › Efficient and distributed learning › data selection
coreset selection
1.012026
Diffusion Reconstruction-based Data Likelihood Estimation for Core-Set Selection · AAAI 2026
Natural language and speech › Language models and text generation
alignment
0.912025
Bridging and Modeling Correlations in Pairwise Data for Direct Preference Optimization · ICLR 2025
Machine learning › Efficient and distributed learning
dataset distillation
0.912025
Influence-Guided Diffusion for Dataset Distillation · ICLR 2025
Natural language and speech › Language models and text generation › preference optimization
direct preference optimization
0.912025
Bridging and Modeling Correlations in Pairwise Data for Direct Preference Optimization · ICLR 2025
Machine learning › Generative modeling › diffusion model
guided diffusion
0.912025
Influence-Guided Diffusion for Dataset Distillation · ICLR 2025
Natural language and speech › Language models and text generation
preference optimization
0.912025
Bridging and Modeling Correlations in Pairwise Data for Direct Preference Optimization · ICLR 2025
Machine learning › Efficient and distributed learning › distillation
adversarial distillation
0.712023
Boosting Accuracy and Robustness of Student Models via Adaptive Adversarial Distillation · CVPR 2023
Machine learning › Efficient and distributed learning › model compression
knowledge distillation
0.712023
Boosting Accuracy and Robustness of Student Models via Adaptive Adversarial Distillation · CVPR 2023
Machine learning › Trustworthy machine learning › adversarial machine learning
adversarial defense
0.512021
Adversarial Defence by Diversified Simultaneous Training of Deep Ensembles · AAAI 2021
Machine learning › Kernel, tree and ensemble methods › ensemble learning
ensemble diversity
0.512021
Adversarial Defence by Diversified Simultaneous Training of Deep Ensembles · AAAI 2021
Machine learning › Trustworthy machine learning
robustness
0.412019
Model-Agnostic Adversarial Detection by Random Perturbations · IJCAI 2019
Security and privacy of machine learning › adversarial defense
adversarial example detection
0.412019
Model-Agnostic Adversarial Detection by Random Perturbations · IJCAI 2019
Machine learning › Probabilistic and Bayesian machine learning › probabilistic inference › approximate inference › variational inference › variational objective
evidence lower bound
0.312026
Diffusion Reconstruction-based Data Likelihood Estimation for Core-Set Selection · AAAI 2026
Machine learning › Trustworthy machine learning › robustness › adversarial robustness
adversarial training
0.212023
Boosting Accuracy and Robustness of Student Models via Adaptive Adversarial Distillation · CVPR 2023

Methods — techniques the papers use, named apart from their topics

partial reverse denoising · 1.0information-theoretic timestep selection · 1.0ELBO · 1.0trajectory influence function · 0.9token-level correlation · 0.9influence functions · 0.9contrastive learning · 0.9robust optimization · 0.7min-max optimization · 0.7adversarial distillation · 0.7random perturbation · 0.4model-agnostic detection · 0.4
YearPublicationVenuePosition
2026 Diffusion Reconstruction-based Data Likelihood Estimation for Core-Set Selection
abstract
Existing core-set selection methods predominantly rely on heuristic scoring signals such as training dynamics or model uncertainty, lacking explicit modeling of data likelihood. This omission may hinder the constructed subset from capturing subtle yet critical distributional structures that underpin effective model training. In this work, we propose a novel, theoretically grounded approach that leverages diffusion models to estimate data likelihood via reconstruction deviation induced by partial reverse denoising. Specifically, we establish a formal connection between reconstruction error and data likelihood, grounded in the Evidence Lower Bound (ELBO) of Markovian diffusion processes, thereby enabling a principled, distribution-aware scoring criterion for data selection. Complementarily, we introduce an efficient information-theoretic method to identify the optimal reconstruction timestep, ensuring that the deviation provides a reliable signal indicative of underlying data likelihood. Extensive experiments on ImageNet demonstrate that reconstruction deviation offers an effective scoring criterion, consistently outperforming existing baselines across selection ratios, and closely matching full-data training using only 50% of the data. Further analysis shows that the likelihood-informed nature of our score reveals informative insights in data selection, shedding light on the interplay between data distributional characteristics and model learning preferences.
Bo Huang 0017, Yi Wang 0017, Wei Wang 0011
AAAI3
2025 When Evolution Strategy Meets Language Models Tuning
abstract
Supervised Fine-tuning has been pivotal in training autoregressive language models, yet it introduces exposure bias. To mitigate this, Post Fine-tuning, including on-policy and off-policy methods, has emerged as a solution to enhance models further. However, each has its limitations regarding performance enhancements and susceptibility to overfitting. In this paper, we introduce a novel on-policy approach called Evolution Strategy Optimization (ESO), which is designed by harnessing the principle of biological evolution, namely survival of the fittest. Particularly, we consider model tuning as an evolution process, and each output sentence generated by the model can provide a perturbation signal to the model parameter space. Then, the fitness of perturbation signals is quantified by the difference between its score and the averaged one offered by a reward function, which guides the optimization process. Empirically, the proposed method can achieve superior performance in various tasks and comparable performance in the human alignment task.
Bo Huang 0017, Yi Wang 0017, Hongyang Chen 0001, Wei Wang 0011
COLING1
2025 Influence-Guided Diffusion for Dataset Distillation
abstract
Dataset distillation aims to streamline the training process by creating a compact yet effective dataset for a much larger original dataset. However, existing methods often struggle with distilling large, high-resolution datasets due to prohibitive resource costs and limited performance, primarily stemming from sample-wise optimizations in the pixel space. Motivated by the remarkable capabilities of diffusion generative models in learning target dataset distributions and controllably sampling high-quality data tailored to user needs, we propose framing dataset distillation as a controlled diffusion generation task aimed at generating data specifically tailored for effective training purposes. By establishing a correlation between the overarching objective of dataset distillation and the trajectory influence function, we introduce the Influence-Guided Diffusion (IGD) sampling framework to generate training-effective data without the need to retrain diffusion models. An efficient guided function is designed by leveraging the trajectory influence function as an indicator to steer diffusions to produce data with influence promotion and diversity enhancement. Extensive experiments show that the training performance of distilled datasets generated by diffusions can be significantly improved by integrating with our IGD method and achieving state-of-the-art performance in distilling ImageNet datasets. Particularly, an exceptional result is achieved on the ImageNet-1K, reaching 60.3\% at IPC=50. Our code is available at https://github.com/mchen725/DD_IGD.
Bo Huang 0017, Yi Wang 0017, Wei Wang 0011
ICLR3
2025 Bridging and Modeling Correlations in Pairwise Data for Direct Preference Optimization
abstract
Direct preference optimization (DPO), a widely adopted offline preference optimization algorithm, aims to align large language models (LLMs) with human-desired behaviors using pairwise preference data. However, the generation of the winning response and the losing response within pairwise data are typically isolated, leading to weak correlations between them as well as suboptimal alignment performance. To address this issue, we propose an effective framework for Bridging and Modeling Correlations in pairwise data, named BMC. Firstly, we increase the consistency and informativeness of the pairwise preference signals through targeted modifications, synthesizing a pseudo-winning response by improving the losing response with the winning response as a reference. Secondly, we identify that DPO alone is insufficient to model these correlations and capture nuanced variations. Therefore, we propose learning token-level correlations by dynamically leveraging the policy model's confidence during training. Comprehensive experiments on QA, math, and instruction-following tasks demonstrate the effectiveness of our approach, significantly surpassing competitive baselines, including DPO. Additionally, our in-depth quantitative analysis reveals the reasons behind our method's superior performance over DPO and showcases its versatility to other DPO variants.
Bo Huang 0017, Yufei Wang 0005, Xingshan Zeng, Liangyou Li, Yasheng Wang, Xin Jiang 0002, Lifeng Shang, Ruiming Tang, Wei Wang 0011
ICLR2
2023 Boosting Accuracy and Robustness of Student Models via Adaptive Adversarial Distillation
abstract
Distilled student models in teacher-student architectures are widely considered for computational-effective deployment in real-time applications and edge devices. However, there is a higher risk of student models to encounter adversarial attacks at the edge. Popular enhancing schemes such as adversarial training have limited performance on compressed networks. Thus, recent studies concern about adversarial distillation (AD) that aims to inherit not only prediction accuracy but also adversarial robustness of a robust teacher model under the paradigm of robust optimization. In the min-max framework of AD, existing AD methods generally use fixed supervision information from the teacher model to guide the inner optimization for knowledge distillation which often leads to an overcorrection towards model smoothness. In this paper, we propose an adaptive adversarial distillation (AdaAD) that involves the teacher model in the knowledge optimization process in a way interacting with the student model to adaptively search for the inner results. Comparing with state-of-the-art methods, the proposed AdaAD can significantly boost both the prediction accuracy and adversarial robustness of student models in most scenarios. In particular, the ResNet-18 model trained by AdaAD achieves top-rank performance (54.23% robust accuracy) on RobustBench under AutoAttack.
Bo Huang 0017, Yi Wang 0017, Junda Lu 0001, Minhao Cheng, Wei Wang 0011
CVPR1
2023 Deep Ensemble Robustness by Adaptive Sampling in Dropout-Based Simultaneous Training
abstract
Recent studies show that an ensemble of deep networks can have better adversarial robustness by increasing the deep feature learning diversity of base models to limit the adversarial transferability. However, existing schemes mostly rely on a second-order method for gradient regularization which usually involves a heavy computation overhead. In this paper, we propose a simple yet effective method which eliminates the use of a second-order optimization and significantly reduces the computation complexity of regularized simultaneous training of deep ensemble networks. For the first time, we show analytically that stochastic regularization by the proposed approach can promote both model smoothness and feature diversity of representation learning in the deep space. We also show that the proposed method is able to achieve a better gain of certified robustness. This is due to the effect of a prioritized feature selection enabled by an adaptive and continuous sampling of neuron activation among the base networks. Experimental results show that our method can improve adversarial robustness significantly comparing with the existing ensemble models on several image benchmark datasets. The ensemble performance can be further boosted by complementing the stochastic regularization approach with other defense paradigms such as adversarial training.
Quanwei Wu, Bo Huang 0017, Yi Wang 0017, Zhiwei Ke
ECAI2
2021 Adversarial Defence by Diversified Simultaneous Training of Deep Ensembles
abstract
Learning-based classifiers are susceptible to adversarial examples. Existing defence methods are mostly devised on individual classifiers. Recent studies showed that it is viable to increase adversarial robustness by promoting diversity over an ensemble of models. In this paper, we propose adversarial defence by encouraging ensemble diversity on learning high-level feature representations and gradient dispersion in simultaneous training of deep ensemble networks. We perform extensive evaluations under white-box and black-box attacks including transferred examples and adaptive attacks. Our approach achieves a significant gain of up to 52% in adversarial robustness, compared with the baseline and the state-of-the-art method on image benchmarks with complex data scenes. The proposed approach complements the defence paradigm of adversarial training, and can further boost the performance. The source code is available at https://github.com/ALIS-Lab/AAAI2021-PDD.
Bo Huang 0017, Zhiwei Ke, Yi Wang 0017, Wei Wang 0011, LinLin Shen, Feng Liu 0013
AAAI1
2019 Model-Agnostic Adversarial Detection by Random Perturbations
abstract
Adversarial examples induce model classification errors on purpose, which has raised concerns on the security aspect of machine learning techniques. Many existing countermeasures are compromised by adaptive adversaries and transferred examples. We propose a model-agnostic approach to resolve the problem by analysing the model responses to an input under random perturbations, and study the robustness of detecting norm-bounded adversarial distortions in a theoretical framework. Extensive evaluations are performed on the MNIST, CIFAR-10 and ImageNet datasets. The results demonstrate that our detection method is effective and resilient against various attacks including black-box attacks and the powerful CW attack with four adversarial adaptations.
Bo Huang 0017, Yi Wang 0017, Wei Wang 0011
IJCAI1